Supply-chain Levels for Software Artifacts
-
Updated
Dec 15, 2025 - Shell
Supply-chain Levels for Software Artifacts
GUAC aggregates software security metadata into a high fidelity graph database.
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
Protect against malicious open source packages 🤖
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
Damn Vulnerable SCA Application
Orchestrate GitHub Actions Security
Hermeto is a CLI tool that prefetches your project dependencies to aid in making your container build process hermetic.
Docker Scout GitHub Action
blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries.
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Packj stops ⚡ Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
A compilation of resources in the software supply chain security domain, with emphasis on open source
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
safely install npm packages by auditing them pre-install stage
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
Add a description, image, and links to the supply-chain-security topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain-security topic, visit your repo's landing page and select "manage topics."