An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
☆774Dec 11, 2024Updated last year
Alternatives and similar repositories for chain-bench
Users that are interested in chain-bench are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆21Nov 24, 2022Updated 3 years ago
- ☆17Sep 4, 2025Updated 10 months ago
- The perfect package to work with packages locally☆18May 28, 2022Updated 4 years ago
- ☆14Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆537Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Generate a score for your sbom to understand if it will actually be useful.☆241Aug 13, 2024Updated last year
- Linux Runtime Security and Forensics using eBPF☆4,552Updated this week
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆874Mar 28, 2025Updated last year
- A reading list for software supply-chain security.☆365Nov 21, 2022Updated 3 years ago
- Security configuration checks for popular cloud native applications and infrastructure.☆119Feb 16, 2022Updated 4 years ago
- Notice: Postee is no longer under active development or maintenance.☆205May 27, 2026Updated last month
- Keyless Git signing using Sigstore☆1,110Updated this week
- OWASP Foundation Web Respository☆615Updated this week
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆624Feb 10, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- in-toto is a framework to protect supply chain integrity.☆1,019Jul 13, 2026Updated last week
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,518Updated this week
- ☆428Jan 18, 2023Updated 3 years ago
- Code signing and transparency for containers and binaries☆6,144Updated this week
- Cloud Security Posture Management (CSPM)☆3,756Feb 23, 2026Updated 4 months ago
- Evaluate source control (GitHub) security posture☆251Mar 8, 2023Updated 3 years ago
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆36,991Updated this week
- Compares and analyzes GCP IAM roles.☆78Mar 9, 2025Updated last year
- Open source compliance tool for development platforms.☆286Oct 30, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,257Updated this week
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆372Jun 7, 2026Updated last month
- Documenting your Threat Models with HCL☆463Updated this week
- Tfsec is now part of Trivy☆7,022Mar 25, 2026Updated 3 months ago
- Supply-chain Levels for Software Artifacts☆1,891Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,589Updated this week
- library for adding comments to git PRs☆15Jun 8, 2026Updated last month
- Vulnerability scanning just got lazier☆326Jul 10, 2026Updated last week
- Language-agnostic SLSA provenance generation for Github Actions☆589Mar 29, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆11May 19, 2025Updated last year
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆73Updated this week
- OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure☆1,462May 25, 2026Updated last month
- Automating situational awareness for cloud penetration tests.☆2,530May 26, 2026Updated last month
- Crowdsourced list of sensitive IAM Actions☆158Oct 29, 2024Updated last year
- Trivy's misconfiguration scanning engine☆214Jan 23, 2025Updated last year
- IAM-Deescalate helps mitigate privilege escalation risk in AWS identity and access management (IAM)☆98Sep 14, 2022Updated 3 years ago