Projects with this topic
-
A fast, minimal viewer for SPDX SBOMs: cascading documents, compliance profiles (NTIA, BSI TR-03183), VEX overlay. Client-side, files never leave your machine.
Updated -
Read-only mirror of cicd-sensor: An open-source runtime security monitoring tool for CI/CD environments leveraging eBPF.
Updated -
Toolchain image for the Coroboros security gates.
UpdatedUpdated -
Lightweight static-analysis scanner for AUR PKGBUILD and .install scripts — detects backdoor patterns, obfuscation, and supply-chain indicators of compromise. Written in Babashka/Clojure.
Updated -
A fast, minimal viewer for Open Component Model deliveries: CTF archives, embedded SBOMs, client-side signature verification, OCI registry browsing.
Updated -
-
A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical strategies to defend against ecosystem threats.
Updated -
Kubernetes-native Helm auditor for supply chain security, aggregating SBOM, vulnerability, and provenance data.
Updated