A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.
☆150Jan 28, 2024Updated 2 years ago
Alternatives and similar repositories for Software-Supply-Chain-Security
Users that are interested in Software-Supply-Chain-Security are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆375Jun 7, 2026Updated 2 months ago
- ☆13Apr 24, 2023Updated 3 years ago
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆599Updated this week
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆82Aug 7, 2026Updated last week
- A reading list for software supply-chain security.☆365Nov 21, 2022Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆116Feb 11, 2026Updated 6 months ago
- 🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)☆54Updated this week
- Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.☆35Apr 4, 2023Updated 3 years ago
- Format agnostic SBOM tooling☆156Nov 20, 2025Updated 8 months ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆111Updated this week
- Websec interview questions by tib3rius answered☆310Nov 13, 2023Updated 2 years ago
- Machine-readable specification for the attestation of security-relevant data.☆81Aug 11, 2026Updated last week
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆40Sep 25, 2024Updated last year
- TACOS framework structural details☆20May 12, 2025Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆70Nov 27, 2025Updated 8 months ago
- A collection of dashboards, templates, API's and Power BI code for vulnerability management and analysis☆23Feb 2, 2025Updated last year
- A place to systematically store software bill of materials (SBOM) documents.☆51Jun 1, 2023Updated 3 years ago
- Build a CVE library with aggregated CISA, EPSS and CVSS data☆29Sep 27, 2023Updated 2 years ago
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆623Jun 2, 2026Updated 2 months ago
- An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchm…☆775Dec 11, 2024Updated last year
- Generate a score for your sbom to understand if it will actually be useful.☆242Aug 13, 2024Updated 2 years ago
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.☆372Updated this week
- A CLI tool for creating secure by design/default source repos.☆28Jul 29, 2024Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain☆98Feb 11, 2025Updated last year
- in-toto Attestation Framework☆368Updated this week
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Jan 4, 2026Updated 7 months ago
- My journey and notes on learning Offensive Security from the ground up☆21Dec 22, 2025Updated 7 months ago
- Data about all known supply-chain attacks through history☆78Updated this week
- Polar is a secure and scalable knowledge graph framework, designed to address the challenges posed by building big data systems in highly…☆25Updated this week
- ☆193May 29, 2026Updated 2 months ago
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆624Feb 10, 2026Updated 6 months ago
- A tool to check the security settings of Github Organizations.☆77Feb 9, 2026Updated 6 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A tool that takes two or more micro SBOMs and composes them into one distributable SBOM☆23Mar 23, 2023Updated 3 years ago
- A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes☆43Nov 28, 2025Updated 8 months ago
- Supply Chain Query Tool☆13May 25, 2022Updated 4 years ago
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆242May 26, 2025Updated last year
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Apr 23, 2024Updated 2 years ago
- Sharing software supply chain security open source projects☆54Dec 19, 2022Updated 3 years ago
- Low-effort reachability analysis for third-party code vulnerabilities.☆22Jul 11, 2023Updated 3 years ago