TUF client CLI written in Go based on the rdimitrov/go-tuf-metadata library.
-
Updated
Jan 13, 2025 - Go
TUF client CLI written in Go based on the rdimitrov/go-tuf-metadata library.
Digital Container Shipping Association (DCSA) API's
A research study on the adoption of blockchain for IoT devices in supply chains, published in Computational Intelligence and Neuroscience (2022). This study explores the integration of blockchain and IoT, proposing a modified RAFT consensus protocol (mRAFT) to enhance scalability and efficiency in Hyperledger based supply chain environments.
Kubernetes Custom Controller + Admission Webhook for CVE Scan (In Progress)
Programmatically audit GitHub Actions workflow dependencies
A lightweight Go library for validating Software Bill of Materials (SBOM) against industry-standard specifications
WeeTracky is a Go-based backend designed to manage the supply chain for small manufacturing businesses, particularly in the jewelry production sector. The application provides features to track products, materials, suppliers, and certifications, offering a comprehensive view of the supply chain.
A comprehensive software artifact scanning and analysis tool for Docker images and filesystems.
ghavm manages version pinning and upgrades for GitHub Actions workflows.
Malicious-PAckageFinder (m-paf) is a command-line tool that detects malicious and risky packages in your software supply chain using SBOM files.
GitHub Action for SecureSBOM
oshka is a tool for extracting nested CI/CD supply chains and executing commands.
fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool's strength.
Trusty Dependency Risk Action
Typosquatting tool that supports OSINT investigations, and designed to operate on multilingual target domains.
Scan GitHub Actions Workflow logs for IOCs
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."