Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Supply Chain Security

Supply Chain Security

33 projects

Showing 33 of 33 projects

npm-check-updates
npm-check-updatesTypeScript

Upgrades your package.json dependencies to the latest versions while preserving existing semantic versioning policies.

#supply-chain-security#version-updater#npm
Stars10.3k
Forks369
Last commit1 day ago
Cosign
CosignGo

A tool for signing and verifying container images and other artifacts using the Sigstore framework.

#supply-chain-security#keyless-signing#container-security
Stars6.2k
Forks771
Last commit2 days ago
zizmor
zizmorRust

A static analysis tool that finds security vulnerabilities and misconfigurations in GitHub Actions workflows.

#supply-chain-security#workflow-analysis#vulnerability-detection
Stars5.9k
Forks223
Last commit1 day ago
scorecard
scorecardGo

Automated security health metrics for open source projects, assessing security best practices and risks.

#supply-chain-security#security-scanning#openssf-scorecard
Stars5.6k
Forks680
Last commit4 days ago
Roave Security Advisories
Roave Security Advisories

A Composer package that blocks installation of PHP dependencies with known security vulnerabilities.

#supply-chain-security#composer#devops
Stars2.9k
Forks111
Last commit1 day ago
DevSecOps
DevSecOps

A curated list of DevSecOps tools, resources, and training materials for integrating security into the development lifecycle.

#supply-chain-security#hacktoberfest#security-training
Stars1.7k
Forks245
Last commit2 years ago
LunaSec
LunaSecTypeScript

Open-source supply chain security scanner that automatically detects vulnerabilities like Log4Shell in dependencies and notifies via GitHub pull requests.

#supply-chain-security#zero-trust#web-security
Stars1.5k
Forks167
Last commit2 years ago
Harden Runner GitHub Action
Harden Runner GitHub ActionTypeScript

A CI/CD security agent that monitors GitHub Actions runners for threats like network egress, file integrity, and process activity.

#supply-chain-security#actions#runners
Stars1.2k
Forks108
Last commit17 days ago
SafeDep/vet
SafeDep/vetGo

A CLI tool for real-time malicious package detection and software supply chain security across multiple ecosystems.

#pypi#rubygems#supply-chain-security
Stars1.1k
Forks104
Last commit2 days ago
lockfile-lint
lockfile-lintJavaScript

A security linter for npm and yarn lockfiles to detect malicious package injections and enforce trust policies.

#supply-chain-security#hacktoberfest#lockfile
Stars866
Forks36
Last commit1 day ago
rust-audit
rust-auditRust

Embed dependency information into Rust binaries for vulnerability auditing in production.

#supply-chain-security#sbom#cargo-subcommand
Stars836
Forks41
Last commit1 month ago
Common Threat Matrix for CI/CD Pipeline
Common Threat Matrix for CI/CD Pipeline

An ATT&CK-like threat matrix mapping adversary tactics and techniques specific to CI/CD pipeline security.

#supply-chain-security#infrastructure-security#security
Stars776
Forks88
Last commit1 month ago
coi
coiPython

A security-hardened container runtime for AI coding agents using Incus system containers with real-time threat detection and credential isolation.

#supply-chain-security#container-security#ai-coding-agents
Stars601
Forks50
Last commit1 day ago
FireEye's Sunburst Countermeasures
FireEye's Sunburst CountermeasuresYARA

Open-source detection rules for identifying SolarWinds SunBurst backdoor activities and related vulnerabilities across multiple security tools.

#supply-chain-security#yara-rules#clamav-signatures
Stars563
Forks198
Last commit3 years ago
Makes
MakesNix

A CI/CD framework powered by Nix for building secure and reproducible software supply chains.

#supply-chain-security#devops#aws-batch
Stars491
Forks45
Last commit10 months ago
NORA
NORARust

A lightweight, single-binary artifact registry supporting Docker, Maven, npm, PyPI, Cargo, and Go with zero dependencies.

#supply-chain-security#artifact-registry#cargo-registry
Stars248
Forks27
Last commit1 day ago
Upload and Scan Files with VirusTotal
Upload and Scan Files with VirusTotalTypeScript

A GitHub Action to upload and scan files for malware using VirusTotal's analysis engine.

#supply-chain-security#actions#virustotal
Stars227
Forks22
Last commit2 days ago
SDLC Infrastructure Threat Framework (SITF)
SDLC Infrastructure Threat Framework (SITF)HTML

A framework for analyzing and defending against supply chain attacks targeting Software Development Lifecycle infrastructure.

#supply-chain-security#attack-framework#vcs-security
Stars172
Forks17
Last commit10 days ago
Living off the pipeline
Living off the pipelineHTML

A research project inventorying RCE-by-design features and code execution risks in CI/CD pipeline tools.

#supply-chain-security#code-execution#workflow-injection
Stars159
Forks14
Last commit2 months ago
Preflight
PreflightGo

A tool to verify scripts and executables by hash to prevent supply chain attacks.

#supply-chain-security#devops#hash-verification
Stars157
Forks45
Last commit3 years ago
verifyfetch
verifyfetchTypeScript

A drop-in library for resumable downloads and streaming integrity verification of large files in the browser.

#supply-chain-security#integrity#streaming-verification
Stars154
Forks1
Last commit3 months ago
Awesome Cloud Build
Awesome Cloud BuildTypeScript

A curated list of high-signal resources for Google Cloud Build, covering CI/CD, security, and modern delivery pipelines.

#supply-chain-security#artifact-registry#google-cloud-platform
Stars118
Forks12
Last commit4 months ago
Dependency Combobulator
Dependency CombobulatorPython

An open-source, modular framework to detect and prevent dependency confusion attacks across multiple package managers.

#supply-chain-security#secure-coding#python-tool
Stars95
Forks7
Last commit2 years ago
CetusGuard
CetusGuardGo

A security proxy that protects Docker daemon sockets by filtering API endpoint calls with configurable rules.

#supply-chain-security#container-security#tls-authentication
Stars88
Forks2
Last commit3 months ago
CycloneDX-PHP-Composer
CycloneDX-PHP-ComposerPHP

A Composer plugin that generates accurate CycloneDX Software Bill of Materials (SBOM) for PHP projects.

#supply-chain-security#software-bill-of-materials#sbom
Stars86
Forks7
Last commit6 days ago
ChainJacking
ChainJackingPython

A tool to detect which Go dependencies are vulnerable to GitHub repository hijacking (RepoJacking) attacks.

#supply-chain-security#python-tool#repojacking
Stars64
Forks15
Last commit2 months ago
DependencyCheck
DependencyCheckJava

OWASP's software composition analysis tool that identifies project dependencies and checks for known vulnerabilities.

#supply-chain-security#software-composition-analysis#continuous-integration
Stars54
Forks27
Last commit10 months ago
snync
snyncJavaScript

A tool to detect and mitigate Dependency Confusion supply chain security risks in npm projects.

#supply-chain-security#npm-security#vulnerability-detection
Stars53
Forks9
Last commit14 days ago
ClawMoat
ClawMoatJavaScript

An open-source firewall for AI agents that prevents data leaks, dangerous tool usage, and supply chain attacks.

#supply-chain-security#agent-security#runtime-monitoring
Stars42
Forks6
Last commit21 days ago
Awesome Container Security
Awesome Container Security

A curated collection of resources for container building and runtime security.

#supply-chain-security#container-security#runtime-security
Stars19
Forks3
Last commit7 years ago
PR sneaking
PR sneakingCSS

Demonstrates methods for sneaking malicious code into GitHub pull requests to raise awareness of supply chain vulnerabilities.

#supply-chain-security#malware-detection#security
Stars11
Forks1
Last commit9 years ago
buildcage
buildcageTypeScript

A Docker build security tool that restricts outbound network access to only allowed domains, preventing supply chain attacks.

#supply-chain-security#container-security#network-isolation
Stars10
Forks0
Last commit22 hours ago
shai-hulud-scanner
shai-hulud-scannerShell

A fast security scanner that detects the Shai Hulud 2.0 npm supply chain attack by checking for malicious files, hashes, and compromised packages.

#supply-chain-security#cve#npm-security
Stars4
Forks0
Last commit6 months ago

Related Tags

#Devsecops21#Security14#Ci Cd9#Github Actions7#Container Security6#Dependency Management6#Open Source Security6#Devops6#Ci Cd Security5#Malware Detection5#Npm4#Vulnerability Scanning4
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub