GitHub 中文社区
回车: Github搜索    Shift+回车: Google搜索
论坛
排行榜
趋势
登录

©2025 GitHub中文社区论坛GitHub官网网站地图GitHub官方翻译

  • X iconGitHub on X
  • Facebook iconGitHub on Facebook
  • Linkedin iconGitHub on LinkedIn
  • YouTube iconGitHub on YouTube
  • Twitch iconGitHub on Twitch
  • TikTok iconGitHub on TikTok
  • GitHub markGitHub’s organization on GitHub
集合主题趋势排行榜
#

supply-chain-security

Website
Wikipedia
https://static.github-zh.com/github_avatars/slsa-framework?size=40
slsa-framework / slsa

Supply-chain Levels for Software Artifacts

安全supply-chain-securityDevOps
Shell 1.67 k
6 天前
https://static.github-zh.com/github_avatars/guacsec?size=40
guacsec / guac

GUAC aggregates software security metadata into a high fidelity graph database.

安全software-supply-chainsoftware-supply-chain-securitysupply-chain-securityattestationsgraphsbomcyclonedxspdxvexvulnerabilityvulnerability-management
Go 1.37 k
4 天前
https://static.github-zh.com/github_avatars/owasp-dep-scan?size=40
owasp-dep-scan / dep-scan

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container ima...

vulnerability-scannersCommon Vulnerabilities and Exposures (CVE)dependency-analysiscontainerssbomscacompliancecyclonedxdevsecops安全vexsupply-chain-security
Python 1.12 k
19 天前
https://static.github-zh.com/github_avatars/tern-tools?size=40
tern-tools / tern

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-...

PythoncontainerssbomDockercompliancespdx工具依赖管理software-composition-analysisrisk-managementOpen Sourcesupply-chain-security
Python 989
1 年前
https://static.github-zh.com/github_avatars/step-security?size=40
step-security / harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-...

Actionssupply-chain-securityhardeningsecurity-hardeningnetwork-securityruntime-security
TypeScript 834
4 天前
https://static.github-zh.com/github_avatars/Legit-Labs?size=40
Legit-Labs / legitify

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

supply-chain-securitysecurity-scannerDevOps安全devsecops持续集成GitHubGitLabGo
Go 811
3 个月前
https://static.github-zh.com/github_avatars/bitbomdev?size=40
bitbomdev / minefield

#大语言模型#Graphing SBOM's Fast.

graphsbomsupply-chain-securityairgap人工智能大语言模型
Go 721
10 天前
https://static.github-zh.com/github_avatars/ossillate-inc?size=40
ossillate-inc / packj

Packj stops ⚡ Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain

MalwarenpmpypiPython安全vulnerabilityrubygemssupply-chain-securitymalware-analysisstatic-analysisvulnerability-scannersdynamic-analysissandboxingDevOpsdeveloper-toolsdevops-toolsdevsecops
Python 668
1 年前
https://static.github-zh.com/github_avatars/safedep?size=40
safedep / vet

Next Generation Software Composition Analysis (SCA) with Malicious Package Detection, Code Context & Policy as Code

devsecops安全supply-chain-securitypolicy-as-codesoftware-composition-analysisGonpmpypirubygemsstatic-analysisHacktoberfest
Go 494
2 天前
https://static.github-zh.com/github_avatars/chainloop-dev?size=40
chainloop-dev / chainloop

Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

compliancecyclonedxdevsecopssbom安全spdxsupply-chain-securitylicenseopen-source-licensingospoattestation
Go 463
5 天前
https://static.github-zh.com/github_avatars/docker?size=40
docker / scout-cli

Docker Scout CLI

Docker安全supply-chain-security
Shell 392
20 天前
https://static.github-zh.com/github_avatars/kpcyrd?size=40
kpcyrd / rebuilderd

Independent verification of binary packages - Reproducible Builds

reproducible-buildssupply-chain-security安全Rust
Rust 385
1 个月前
https://static.github-zh.com/github_avatars/owasp-dep-scan?size=40
owasp-dep-scan / blint

BLint is a Binary Linter to check the security properties, and capabilities in your executables. Since v2, blint is also an SBOM generator for binaries.

binaryFuzzing/Fuzz testingMalwarecyclonedxsbomsupply-chain-security
Python 380
8 天前
https://static.github-zh.com/github_avatars/bureado?size=40
bureado / awesome-software-supply-chain-security

#Awesome#A compilation of resources in the software supply chain security domain, with emphasis on open source

reproducible-buildssupply-chain-securitydevsecopsvulnerability-scanning安全vulnerability-managementsbompackage-management依赖管理static-analysissoftware-composition-analysissoftware-supply-chainsoftware-supply-chain-securitycve-scanningattestationAwesome Lists
322
2 年前
https://static.github-zh.com/github_avatars/boostsecurityio?size=40
boostsecurityio / poutine

boostsecurityio/poutine

持续集成命令行界面DevOpsdevsecopsGitHubActionsGo安全security-scannersupply-chain-securityGitHub CLI extension
Go 297
9 天前
https://static.github-zh.com/github_avatars/step-security?size=40
step-security / secure-repo

Orchestrate GitHub Actions Security

安全ActionsworkflowGitHubGosupply-chain-security
Go 289
10 天前
https://static.github-zh.com/github_avatars/buildsafedev?size=40
buildsafedev / bsf

Developer-centric tool to secure your software supply chain.

Nixreproducibilitysupply-chain-securityHacktoberfest
Go 289
6 个月前
https://static.github-zh.com/github_avatars/NodeSecure?size=40
NodeSecure / js-x-ray

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

安全ParsingJavaScriptNode.jssastsupply-chain-security
JavaScript 252
4 天前
https://static.github-zh.com/github_avatars/apiiro?size=40
apiiro / PRevent

Prevent merging of malicious code in pull requests

cloud-securitycode-securitygithub-appmalware-detectionobfuscationpull-requestsecurity-scan安全semgrepstatic-analysissupply-chain-security
Python 225
3 个月前
https://static.github-zh.com/github_avatars/interlynk-io?size=40
interlynk-io / sbomqs

SBOM Assess - Evaluate SBOM quality and compliance

Gocyclonedxspdxsbomdevsecops-pipeline安全supply-chain-security
Go 213
4 天前
loading...