Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
-
Updated
Jul 30, 2025 - Python
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
in-toto is a framework to protect supply chain integrity.
Packj stops ⚡ Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
Environments for OR and RL Research
A Sigstore client written in Python
Supply chain security for ML
A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.
Software Component Verification Standard (SCVS)
Python inventory optimization and simulation tools.
Improve Warehouse Productivity using Order Batching
Security audit Python project dependencies against security advisory databases.
Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks
A GitHub Action for sigstore-python
A command line tool for detecting vulnerabilities in Python dependencies and doing safe package installs
OtterDog is a tool to manage GitHub organizations at scale using a configuration as code approach. It is actively used by the Eclipse Foundation to manage its numerous projects hosted on GitHub.
Supply Chain Integrity Transparency and Trust ledger application using Confidential Consortium Framework (CCF)
Check remote repositories for typical red flags like CLAs and risks due to low development activity
A Python library to design & optimize Supply Chains
Design a Telegram Bot that will interact with truck drivers to track your shipments and provide real-time visibility of your transportation performance using Python Flask
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."