Automated security testing for open source libraries and applications.
-
Updated
Sep 18, 2022 - Rust
Automated security testing for open source libraries and applications.
Comparing crates.io contents with the corresponding Git repositories to check for supply chain attacks.
Experimental pacman integration for Reproducible Builds and Binary Transparency (with sigstore/rekor)
Advanced AI-based supply-chain security intelligence for Go projects.
基于Rust,Vite,MySQL的供应商与零件关系管理系统
nix2sbom extracts the CycloneDX and SPDX SBOM (Software Bill of Materials) from a Nix derivation
Fast OSV vulnerability lookups across ecosystems (Rust + Clap CLI)
📦 Decentralized Supply Chain - Transparent provenance tracking with Byzantine-resistant consensus
Know your dependencies via interactive cargo dependency graph visualization. An opinionated fork of cargo-depgraph that focuses on interactivity.
atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.
Independent verification of binary packages - Reproducible Builds
A production-ready Rust crate for auditing dependency health, maintenance status, license compliance, and footprint risk in Rust projects. Includes both a library API and CLI tool.
Konarr: A free and open source SCA platform for your containers
Command line interface for the Phylum API
Get trusted publishing and build reproducibility insights for any Rust supply chain
Add a description, image, and links to the supply-chain topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain topic, visit your repo's landing page and select "manage topics."