A proof-of-concept SLSA provenance generator for Buildkite.
-
Updated
Oct 20, 2021 - Go
A proof-of-concept SLSA provenance generator for Buildkite.
A malicious package to demonstrate the importance of software supply chain security.
SLSA level 3 action
Github Action implementation of SLSA Provenance Generation
A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.
Software Supply Chain Security Platform
An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
GUAC aggregates software security metadata into a high fidelity graph database.
An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。
Add a description, image, and links to the software-supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the software-supply-chain topic, visit your repo's landing page and select "manage topics."