supply-chain-security
Tracked open-source repos tagged supply-chain-security, sorted by stars.
Related topics
Topics that frequently appear alongside supply-chain-security on the same repo.
Recent risers
Repos created in the last 90 days, tagged supply-chain-security.
No new repos tagged with this topic in the last 90 days.
- #1
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
★ 15,711+515Star change over the last 7 days - #2
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
★ 4,985+7Star change over the last 7 days - #3
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
★ 3,925+42Star change over the last 7 days - #4
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
★ 2,699+7Star change over the last 7 days - #5★ 1,921+5Star change over the last 7 days
- #6★ 1,791+2Star change over the last 7 days
- #7★ 1,537+3Star change over the last 7 days
- #8
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
★ 1,282+0Star change over the last 7 days - #9
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
★ 1,259+1Star change over the last 7 days - #10
Collection of npm package manager Security Best Practices
★ 1,250+1Star change over the last 7 days - #11★ 1,103+0Star change over the last 7 days
- #12
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
★ 1,020+2Star change over the last 7 days - #13
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
★ 882+0Star change over the last 7 days - #14
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API key needed, JSON and SARIF output.
★ 839+13Star change over the last 7 days - #15
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
★ 824+7Star change over the last 7 days - #16
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
★ 692+1Star change over the last 7 days - #17
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
★ 583+0Star change over the last 7 days - #18
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
★ 569—Star change over the last 7 days - #19★ 512+2Star change over the last 7 days
- #20
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
★ 510+5Star change over the last 7 days