in-toto is a framework to protect supply chain integrity.
-
Updated
Dec 9, 2025 - Python
in-toto is a framework to protect supply chain integrity.
Environments for OR and RL Research
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them
A Sigstore client written in Python
Supply chain security for ML
Software Component Verification Standard (SCVS)
Improve Warehouse Productivity using Order Batching
Packj stops ⚡ Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
Python inventory optimization and simulation tools.
Repository Service for TUF: Command Line Interface
Supply Chain Integrity Transparency and Trust ledger application using Confidential Consortium Framework (CCF)
Design a Telegram Bot that will interact with truck drivers to track your shipments and provide real-time visibility of your transportation performance using Python Flask
OtterDog is a tool to manage GitHub organizations at scale using a configuration as code approach. It is actively used by the Eclipse Foundation to manage its numerous projects hosted on GitHub.
Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks
Security audit Python project dependencies against security advisory databases.
A GitHub Action for sigstore-python
A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.
Perform demand forecasting at the part level rather than the aggregate level to minimize disruptions in your supply chain and increase sales. Manage material shortages and predict overplanning
Allow to exchange file datas between Odoo ERP and external warehouses
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."