An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
☆772Dec 11, 2024Updated last year
Alternatives and similar repositories for chain-bench
Users that are interested in chain-bench are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆21Nov 24, 2022Updated 3 years ago
- ☆17Sep 4, 2025Updated last year
- The perfect package to work with packages locally☆18May 28, 2022Updated 4 years ago
- ☆15Sep 1, 2026Updated 2 weeks ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆546Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- Linux Runtime Security and Forensics using eBPF☆4,618Updated this week
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆887Aug 31, 2026Updated 2 weeks ago
- A reading list for software supply-chain security.☆365Nov 21, 2022Updated 3 years ago
- Security configuration checks for popular cloud native applications and infrastructure.☆119Feb 16, 2022Updated 4 years ago
- Threat matrix for CI/CD Pipeline☆772May 31, 2026Updated 3 months ago
- Notice: Postee is no longer under active development or maintenance.☆204Aug 31, 2026Updated 2 weeks ago
- Keyless Git signing using Sigstore☆1,126Updated this week
- OWASP Foundation Web Respository☆621Sep 11, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆624Feb 10, 2026Updated 7 months ago
- in-toto is a framework to protect supply chain integrity.☆1,040Aug 27, 2026Updated 3 weeks ago
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,541Updated this week
- ☆429Jan 18, 2023Updated 3 years ago
- Code signing and transparency for containers and binaries☆6,315Updated this week
- Cloud Security Posture Management (CSPM)☆3,776Sep 7, 2026Updated last week
- Evaluate source control (GitHub) security posture☆251Mar 8, 2023Updated 3 years ago
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆37,982Updated this week
- Compares and analyzes GCP IAM roles.☆78Mar 9, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Open source compliance tool for development platforms.☆286Oct 30, 2023Updated 2 years ago
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,583Updated this week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆380Jun 7, 2026Updated 3 months ago
- Documenting your Threat Models with HCL☆465Updated this week
- Tfsec is now part of Trivy☆7,038Mar 25, 2026Updated 5 months ago
- Supply-chain Levels for Software Artifacts☆1,928Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,697Updated this week
- library for adding comments to git PRs☆16Aug 19, 2026Updated last month
- Vulnerability scanning just got lazier☆329Aug 1, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Language-agnostic SLSA provenance generation for Github Actions☆600Aug 7, 2026Updated last month
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆10May 19, 2025Updated last year
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆74Updated this week
- OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure☆1,459May 25, 2026Updated 3 months ago
- Automating situational awareness for cloud penetration tests.☆2,579Aug 20, 2026Updated 3 weeks ago
- Crowdsourced list of sensitive IAM Actions☆158Oct 29, 2024Updated last year
- Trivy's misconfiguration scanning engine☆214Jan 23, 2025Updated last year