Aggregate view of all dependabot findings
-
Updated
Apr 23, 2023 - Go
Aggregate view of all dependabot findings
🛠️📊🤖 Fake GitHub Activity Generator
The Cartographer CLI offers a convenient way to manage a Cartographer installation and related workflows.
An example of something terrible in plain sight
Malicious-PAckageFinder (m-paf) is a command-line tool that detects malicious and risky packages in your software supply chain using SBOM files.
Go dependencies parser and formatter
Security wrapper for package managers using a local MITM proxy and the OSSF malicious-packages DB to block malware before install.
Scan for vulnerabilities and trace their usage in your source code
Static analysis tool to Identify and Fix GitHub Actions prone to Supply‑Chain Risks
Go API client for osv.dev
A lightweight Go library for validating Software Bill of Materials (SBOM) against industry-standard specifications
A pure client side Bitbucket Pipe containing a collection of open source tools to perform various types of additional analysis on a CycloneDX or SPDX sBOM (Software Bill of Materials).
The lockfile for the agentic web: snapshot and sign MCP server capabilities (Ed25519 or Sigstore), detect drift, enforce CEL policy.
Pin your 3rd Party Github Actions and Docker Images dependencies.
Sample Go application project with supply chain security workflows conforms to the SLSA Build Level 3 specification
SBOM Move - Automate build and transfer of SBOMs across systems
Add a description, image, and links to the supply-chain-security topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain-security topic, visit your repo's landing page and select "manage topics."