Independent verification of binary packages - Reproducible Builds
-
Updated
Dec 5, 2025 - Rust
Independent verification of binary packages - Reproducible Builds
Command line interface for the Phylum API
Experimental pacman integration for Reproducible Builds and Binary Transparency (with sigstore/rekor)
atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.
Know your dependencies via interactive cargo dependency graph visualization. An opinionated fork of cargo-depgraph that focuses on interactivity.
nix2sbom extracts the CycloneDX and SPDX SBOM (Software Bill of Materials) from a Nix derivation
Konarr: A free and open source SCA platform for your containers
Automated security testing for open source libraries and applications.
Advanced AI-based supply-chain security intelligence for Go projects.
Get trusted publishing and build reproducibility insights for any Rust supply chain
📦 Decentralized Supply Chain - Transparent provenance tracking with Byzantine-resistant consensus
基于Rust,Vite,MySQL的供应商与零件关系管理系统
A production-ready Rust crate for auditing dependency health, maintenance status, license compliance, and footprint risk in Rust projects. Includes both a library API and CLI tool.
Comparing crates.io contents with the corresponding Git repositories to check for supply chain attacks.
Fast OSV vulnerability lookups across ecosystems (Rust + Clap CLI)
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."