Throw a tag at it and it comes back with a checksum.
-
Updated
Dec 13, 2025 - Go
Throw a tag at it and it comes back with a checksum.
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
A tool to create, transform and attest VEX metadata
Scan GitHub Actions Workflow logs for IOCs
Software Supply Chain Security Platform
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
Official GitHub Action for OpenSSF Scorecard.
CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.
Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations
Software Supply Chain Transparency Log
Signature Transparency Log designed for ease of use, low cost, and minimal maintenance
OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure
GUAC aggregates software security metadata into a high fidelity graph database.
boostsecurityio/poutine
Go implementation of The Update Framework (TUF)
A lightweight Go library for validating Software Bill of Materials (SBOM) against industry-standard specifications
oshka is a tool for extracting nested CI/CD supply chains and executing commands.
GitHub Action for SecureSBOM
Programmatically audit GitHub Actions workflow dependencies
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."