Software Supply Chain Transparency Log
-
Updated
Dec 8, 2025 - Go
Software Supply Chain Transparency Log
GUAC aggregates software security metadata into a high fidelity graph database.
OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure
Go implementation of The Update Framework (TUF)
Official GitHub Action for OpenSSF Scorecard.
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Software Supply Chain Security Platform
Go implementation of Centrifuge POD (Private Off-chain Data) node
boostsecurityio/poutine
A tool to create, transform and attest VEX metadata
Throw a tag at it and it comes back with a checksum.
Signature Transparency Log designed for ease of use, low cost, and minimal maintenance
Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.
KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems
Cryptographic, immutable, append only software release ledger.
A P2P blockchain network created using Golang!
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."