TUF client CLI written in Go based on the rdimitrov/go-tuf-metadata library.
-
Updated
Jan 13, 2025 - Go
TUF client CLI written in Go based on the rdimitrov/go-tuf-metadata library.
Digital Container Shipping Association (DCSA) API's
Programmatically audit GitHub Actions workflow dependencies
WeeTracky is a Go-based backend designed to manage the supply chain for small manufacturing businesses, particularly in the jewelry production sector. The application provides features to track products, materials, suppliers, and certifications, offering a comprehensive view of the supply chain.
ghavm manages version pinning and upgrades for GitHub Actions workflows.
Malicious-PAckageFinder (m-paf) is a command-line tool that detects malicious and risky packages in your software supply chain using SBOM files.
GitHub Action for SecureSBOM
A research study on the adoption of blockchain for IoT devices in supply chains, published in Computational Intelligence and Neuroscience (2022). This study explores the integration of blockchain and IoT, proposing a modified RAFT consensus protocol (mRAFT) to enhance scalability and efficiency in Hyperledger based supply chain environments.
A comprehensive software artifact scanning and analysis tool for Docker images and filesystems.
oshka is a tool for extracting nested CI/CD supply chains and executing commands.
Kubernetes Custom Controller + Admission Webhook for CVE Scan (In Progress)
A lightweight Go library for validating Software Bill of Materials (SBOM) against industry-standard specifications
Embedded IoT sensor system for harvesting environment data and publishing it onto the permissioned blockchain network
Trusty Dependency Risk Action
Hyperledger Fabric network for IoT enabled permissioned blockchain with sensor requirements control Smart Contracts
A P2P blockchain network created using Golang!
Cryptographic, immutable, append only software release ledger.
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."