Skip to main content
buildradar
Sign in
Topic · supply-chain-security

supply-chain-security

Tracked open-source repos tagged supply-chain-security, sorted by stars.

Repos
20
Total stars
43,000
Avg. stars
2,150
Share
0.00%

Topics that frequently appear alongside supply-chain-security on the same repo.

Recent risers

Repos created in the last 90 days, tagged supply-chain-security.

No new repos tagged with this topic in the last 90 days.

  • SkillSpector@NVIDIA

    Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

    15,711+515Star change over the last 7 days
  • bumblebee@perplexityai

    Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.

    4,985+7Star change over the last 7 days
  • nono@nolabs-ai

    secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

    3,925+42Star change over the last 7 days
  • tirith@sheeki03

    Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.

    2,699+7Star change over the last 7 days
  • slsa@slsa-framework

    Supply-chain Levels for Software Artifacts

    1,921+5Star change over the last 7 days
  • npq@lirantal

    safely install npm packages by auditing them pre-install stage

    1,791+2Star change over the last 7 days
  • guac@guacsec

    GUAC aggregates software security metadata into a high fidelity graph database.

    1,537+3Star change over the last 7 days
  • dep-scan@owasp-dep-scan

    OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

    1,282+0Star change over the last 7 days
  • harden-runner@step-security

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

    1,259+1Star change over the last 7 days
  • Collection of npm package manager Security Best Practices

    1,250+1Star change over the last 7 days
  • vet@safedep

    Protect against malicious open source packages 🤖

    1,103+0Star change over the last 7 days
  • tern@tern-tools

    Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

    1,020+2Star change over the last 7 days
  • legitify@Legit-Labs

    Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

    882+0Star change over the last 7 days
  • ship-safe@asamassekou10

    The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API key needed, JSON and SARIF output.

    839+13Star change over the last 7 days
  • api-relay-audit@toby-bridges

    Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.

    824+7Star change over the last 7 days
  • packj@ossillate-inc

    Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain

    692+1Star change over the last 7 days
  • chainloop@chainloop-dev

    SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

    583+0Star change over the last 7 days
  • hol-guard@hashgraph-online

    Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.

    569Star change over the last 7 days
  • poutine@boostsecurityio

    poutine, a supply chain vulnerability scanner for build pipelines

    512+2Star change over the last 7 days
  • pmg@safedep

    PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

    510+5Star change over the last 7 days
← Back to topics