awesome-software-supply-chain-security
A compilation of resources in the software supply chain security domain, with emphasis on open source
https://github.com/bureado/awesome-software-supply-chain-security
Last synced: 12 days ago
JSON representation
-
About this list
- here
- Add Bad Design as a supply chain scenario · Issue #249 · slsa-framework/slsa - framework/slsa](https://github.com/slsa-framework/slsa/issues/276). [Check out this tweet from Aeva Black](https://twitter.com/aevavoom/status/1491479149227118597) with Dan Lorenc for another in-a-pinch view of a couple key projects.
- supply-chain-synthesis - form read on why that's the case, plus helpful pointers to understand and navigate it as it evolves.
- supply-chain-synthesis - form read on why that's the case, plus helpful pointers to understand and navigate it as it evolves.
- here
-
Build techniques
-
Supply chain beyond libraries
- Reproducible Builds - builds.org/docs/)
- r-b ecosytem mapping
- Is NixOS Reproducible?
- Bootstrappable Builds (GNU Mes Reference Manual)
- Bootstrappable builds
- Verifiable Supply Chain Metadata for Tekton - CD Foundation
- Reproducible Builds: Debian and the case of the missing version string - vulns.xyz
- tag-security/sscsp.md at main · cncf/tag-security
- Inputs - Hoppr
- Draft: POC Witness Runner integration (!1) · Merge requests · testifysec / gitlab-runner
- Software Supply Chain Attestation the Easy Way
- Using Landlock to Sandbox GNU Make
- Changelog
- Bazel
- FOSDEM 2023 - Build recorder: a system to capture detailed information
- reproducible-builds
- Dependency management
- Handling build-time dependency vulnerabilities - security](https://github.com/cncf/tag-security/issues/855)
- Code Sight
- What Makes a Build Reproducible, Part 2
- Building a Secure Software Supply Chain with GNU Guix
- On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software Vulnerabilities
- Reproducible Builds: Break a log, good things come in trees
- Secure Your Software Factory with melange and apko
- Lockheed Martin / hoppr / hoppr
- Reproducible Builds / reprotest
- tektoncd/chains: Supply Chain Security in Tekton Pipelines
- google/santa: A binary authorization system for macOS
- fepitre/package-rebuilder: Standalone orchestrator for rebuilding Debian, Fedora and Qubes OS packages in order to generate `in-toto` metadata which can be used with `apt-transport-in-toto` or `dnf-plugin-in-toto` to validate reproducible status.
- kpcyrd/rebuilderd-debian-buildinfo-crawler: Reproducible Builds: Scraper/Parser for https://buildinfos.debian.net into structured data
- kpcyrd/rebuilderd: Independent verification of binary packages - reproducible builds
- edgelesssys/constellation: Constellation is the first Confidential Kubernetes. Constellation shields entire Kubernetes clusters from the (cloud) infrastructure using confidential computing.
- reposaur/reposaur: Open source compliance tool for development platforms.
- buildsec/frsca - toto attesttations for SLSA provenance predicates.
- chainloop-dev/chainloop: Chainloop is an open source software supply chain control plane, a single source of truth for artifacts plus a declarative attestation crafting process.
- aquasecurity/chain-bench: an open-source tool for auditing your software supply chain stack for security compliance - 1.0/)
- ossf/allstar: GitHub App to set and enforce security policies
- scribe-public/gitgat: Evaluate source control (GitHub) security posture
- Legit-Labs/legitify: Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
- crashappsec/github-analyzer: A tool to check the security settings of Github Organizations.
- wspr-ncsu/github-actions-security-analysis
- jart/landlock-make: Sandboxing for GNU Make has never been easier
- veraison/veraison: Project Veraison will build software components that can be used to build Attestation Verification Services
- GoogleContainerTools/kaniko: Build Container Images In Kubernetes
- sethvargo/ratchet: A tool for securing CI/CD workflows with version pinning.
- buildsec/vendorme
- eellak/build-recorder
- step-security/harden-runner: Security agent for GitHub-hosted runner: block egress traffic & detect code overwrite to prevent breaches
- cider-security-research/cicd-goat: A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
- alecmocatta/build_id: Obtain a UUID uniquely representing the build of the current binary.
- Shopify/hansel
- kpcyrd/archlinux-inputs-fsck: Lint repository of PKGBUILDs for cryptographically pinned inputs
- Software Supply Chain Attestation the Easy Way
- Dependency management
- Software Supply Chain Attestation the Easy Way
- Security hardening for GitHub Actions
- Is NixOS truly reproducible? - Examines bitwise reproducibility claims and challenges in the Nix ecosystem
- google/oss-rebuild: Automate reproducible building and generate SLSA Provenance for Python, JavaScript/TypeScript, and Rust packages to detect supply chain compromises
- appsec-jedi/pipeline-sentinel: eBPF-powered security monitor for CI/CD build pipelines detecting and blocking suspicious process executions to prevent supply chain attacks during the build phase
- aws/uefi: AWS firmware for Nitro instances with reproducible builds to verify measurements against source code
- Azure-Samples/microsoft-azure-attestation: Confidential Compute attestation service examples including measurement verification in JWT certificates
- Attestation concepts
- kusaridev/skootrs - by-design/default source repos with security best practices built in
- MediaMarktSaturn/technolinator - request vulnerability analysis and SBOM creation/upload to Dependency-Track, wrapping CDXGen, SBOMQS, and dep-scan/Grype
- Fraunhofer-AISEC/supply-graph: Graph-based analysis tool for detecting supply chain attacks in build systems by tracing source-to-binary relationships (research/FOSDEM 2025 demonstration project using XZ CVE-2024-3094)
- Pinning GitHub Actions
- rust-secure-code/cargo-auditable: Embed the Cargo dependency tree in your Rust binaries - audit, Trivy, Grype, and other tools
- apiiro/PRevent: Self-hosted GitHub app that scans pull requests for malicious code patterns including dynamic code execution and obfuscation
- SpecterOps/GitHound: BloodHound OpenGraph collector for GitHub mapping organizational structure, permissions, and roles into navigable attack-path graphs for security audits
- StepSecurity Action Advisor
- securego/gosec: Go static analysis tool that detects security problems by scanning the Go AST, enforcing secure coding practices
- hermetoproject/hermeto: CLI tool that pre-fetches dependencies to enable hermetic builds with explicit, reproducible, and pinned dependencies for network-isolated container builds
- garnix-io/garn: Build tool and development environment manager using declarative TypeScript configuration to encode project dependencies, build steps, and development environment in a single reproducible definition
- JReleaser
- Lind-Project/TriSeal (Enarx): WebAssembly-based runtime for executing applications in Trusted Execution Environments (TEEs) such as Intel SGX and AMD SEV-SNP to enable confidential computing for supply chain workloads
- globocom/huskyCI: Orchestrates security tests and centralizes results for analysis and metrics across multiple languages (Python, Ruby, JavaScript, Go, Java, HCL)
- project-copacetic/copacetic: CLI tool for directly patching container images using vulnerability reports from scanners like Trivy, enabling targeted OS package updates without rebuilding images
- trailofbits/buttercup: AI-driven cyber reasoning system for automated vulnerability discovery and patching in open-source code repositories using fuzzing and multi-agent LLM-based patching
- knostic/OpenAnt: LLM-based vulnerability discovery tool for proactively finding verified security flaws while minimizing false positives and negatives, supporting Go, Python, JavaScript/TypeScript, C/C++, PHP, and Ruby
- trailofbits/build-wrap: Linker replacement to sandbox build scripts using Bubblewrap (Linux) or sandbox-exec (macOS), protecting against malicious build script execution
- dash14/buildcage: Restricts outbound network access during Docker builds per RUN step via SNI-based domain filtering, working as a drop-in BuildKit remote driver with ready-to-use GitHub Actions
- stagex.tools: Decentralized, bootstrappable, reproducible Linux distribution with native OCI layer support and Containerfile-based build definitions
- zizmor: Static analysis for GitHub Actions workflows to identify insecure CI/CD patterns
- defenseunicorns/zarf: DevSecOps for Air Gap & Limited-Connection Systems. https://zarf.dev/
- Lockheed Martin / hoppr / hoppr
- oss-reproducible - Measures the reproducibility of a package based on its purported source. Part of [OSS Gadget](https://github.com/microsoft/OSSGadget)
- Changelog
- FOSDEM 2023 - Build recorder: a system to capture detailed information
- Code Sight
- step-security/attack-simulator: Simulate past supply chain attacks such as SolarWinds, Codecov, and ua-parser-js
-
-
Dependency intelligence
-
SCA and SBOM
- GitBOM
- GitBOM. It’s not Git or SBOM
- bomsage/vision.md at main · dpp/bomsage
- SCA tools
- Mend SCA SBOM - developer-tools/bolt/) and [Whitesource Renovate: Automated Dependency Updates](https://www.whitesourcesoftware.com/free-developer-tools/renovate/)
- Use Cases - Renovate Docs
- JFrog Xray - Universal Component Analysis & Container Security Scanning
- Good read on Dependency-Track
- New `docker sbom` Command Creates SBOMs Using Syft
- Creating SBOM Attestations Using Syft and Sigstore
- utils/ci/github/docker-build-sign-sbom at main · marco-lancini/utils
- ANNOUNCE: Scan is now in maintenance mode · Issue #352 · ShiftLeftSecurity/sast-scan
- Container Security | Qualys, Inc.
- Aqua Cloud Native Security, Container Security & Serverless Security
- REA-Products/C-SCRM-Use-Case at master · rjb4standards/REA-Products
- DWARF 5 Standard
- Software Identification (SWID) Tagging | CSRC
- Concise Software Identification Tags
- thread
- in coreboot
- Security problem management
- SBOM Solution
- Supported Languages & Manifests
- Software Bill of Materials
- SBOM Studio
- Software Assurance Guardian Point Man (SAG-PM)
- SCA to Automate Security Scanning
- Enterprise Edition - BluBracket: Code Security & Secret Detection
- Software Composition Analysis (SCA) | CyberRes
- Nexus Intelligence - Sonatype Data Services
- Sonatype BOM Doctor
- Dependency submission
- Brakeing Down Security Podcast: 2020-031-Allan Friedman, SBOM, software transparency, and knowing how the sausage is made
- Episode 312: The Legend of the SBOM
- Tech Debt Burndown Podcast Series 1 E11: Allan Friedman and SBOMs
- Sounil Yu on SBOMs, software supply chain security - Security Conversations
- Exploring Security. Criticality of SBOM. Scott McGregor, Cloud Security, Wind River
- Down the Security Rabbithole Podcast: DtSR Episode 487 - Software Supply Chain is a BFD
- Software Composition Analysis Podcast: Software Supply Chain - Episode 1
- Critical Update: Do You Know What’s In Your Software?
- Software Bill of Materials | CISA
- SBOM Hub - NTIA Attribute Mappings
- BOF: SBOMs for Embedded Systems: What's Working, What's Not? - Kate Stewart, Linux Foundation
- All About That BoM, ‘bout That BoM - Melba Lopez, IBM
- SBOM Management | Six Ways It Prevents SBOM Sprawl
- The Minimum Elements For a Software Bill of Materials
- What an SBOM Can Do for You
- envoy/DEPENDENCY_POLICY.md at main · envoyproxy/envoy
- What curl expects from dependencies
- GitBOM. It’s not Git or SBOM
- Rezillion Dynamic SBOM
- awesomeSBOM/awesome-sbom
- git-bom/bomsh: bomsh is collection of tools to explore the GitBOM idea
- yonhan3/gitbom-repo: A repository of gitBOM docs for Linux binaries
- Grafeas: A Component Metadata API
- trailofbits/it-depends: A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.
- renovatebot/renovate: Universal dependency update tool that fits into your workflows.
- DependencyTrack/dependency-track: Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
- oss-review-toolkit/ort: A suite of tools to assist with reviewing Open Source Software dependencies.
- anchore/syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems
- tern-tools/tern: Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
- Phylum Analyze PR Action: GitHub Action to analyze Pull Requests for open-source supply chain issues
- microsoft/component-detection: Scans your project to determine what components you use
- hughsie/python-uswid: A tiny tool for embedding CoSWID tags in EFI binaries
- DefectDojo/django-DefectDojo: DefectDojo is a DevSecOps and vulnerability management tool.
- DefectDojo/sample-scan-files: Sample scan files for testing DefectDojo imports
- swingletree-oss/swingletree: Integrate and observe the results of your CI/CD pipeline tools
- mercedes-benz/sechub: SecHub - one central and easy way to use different security tools with one API/Client
- BBVA/susto: Systematic Universal Security Testing Orchestration
- AppThreat/rosa: An experiment that looks very promising so far.
- opensbom-generator/spdx-sbom-generator: Support CI generation of SBOMs via golang tooling.
- javixeneize/yasca: Yet Another SCA tool
- edgebitio/edgebit-build: GitHub action to upload SBOMs to EdgeBit and receive vulnerability context in your pull requests - Real-time supply chain security, enabling security teams to target and coordinate vulnerability remediation without toil.](https://edgebit.io/)
- microsoft/sbom-tool: The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts
- sbs2001/fatbom: fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool's strength.
- jhutchings1/spdx-to-dependency-graph-action: A GitHub Action that takes SPDX SBOMs and uploads them to GitHub's dependency submission API to power Dependabot alerts
- evryfs/sbom-dependency-submission-action: Submit SBOMs to GitHub's dependency submission API
- tap8stry/orion: Go beyond package manager discovery for SBOM
- patriksvensson/covenant: A tool to generate SBOM (Software Bill of Material) from source code artifacts.
- CycloneDX/cyclonedx-webpack-plugin: Create CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.
- advanced-security/gh-sbom: Generate SBOMs with gh CLI
- interlynk-io/sbomqs: SBOM quality score - Quality metrics for your sboms
- eBay/sbom-scorecard: Generate a score for your sbom to understand if it will actually be useful.
- Reimagining Cyber Podcast: Log4j vulnerability provides harsh lessons in unknown dependencies
- Mend SCA SBOM - developer-tools/bolt/) and [Whitesource Renovate: Automated Dependency Updates](https://www.whitesourcesoftware.com/free-developer-tools/renovate/)
- SBOM Use Case - RKVST - RKVST](https://www.rkvst.com/rkvst-sbom-hub/)
- Reimagining Cyber Podcast: Log4j vulnerability provides harsh lessons in unknown dependencies
- Software Composition Analysis (SCA) | CyberRes
- DWARF 5 Standard
- marcinguy/betterscan-ce: Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners with One Report (Code, IaC) - Betterscan Community Edition (CE)
- nexB/scancode-toolkit: ScanCode detects licenses, copyrights, package manifests & dependencies and more by scanning code ... to discover and inventory open source and third-party packages used in your code.
- SBOM Use Case - RKVST - RKVST](https://www.rkvst.com/rkvst-sbom-hub/)
- Enterprise Edition - BluBracket: Code Security & Secret Detection
- Reimagining Cyber Podcast: Log4j vulnerability provides harsh lessons in unknown dependencies
- Software Composition Analysis Podcast: Software Supply Chain - Episode 1
- Energy SBOM Proof of Concept - INL
- AppThreat/dep-scan: Fully open-source security audit for project dependencies based on known vulnerabilities and advisories. Supports both local repos and container images. Integrates with various CI environments such as Azure Pipelines, CircleCI, Google CloudBuild. No server required!
- guacsec/trustify - referencing against security advisories to identify vulnerabilities. See [docs](https://docs.trustification.dev/trustify/index.html)
- trustification/trustification: A collection of services for storing and managing SBOMs and VEX documents
- eclipse-sw360/sw360
- e-m-b-a/emba: Security analyzer for firmware of embedded devices, supporting static and dynamic analysis via emulation, SBOM generation, and vulnerability reporting
- SBOM tools
- DeepBOM - powered platform for SBOM management, vulnerability assessment, malware detection and license compliance
- SoftwareDesignLab/SBOM-in-a-Box
- philips-software/SPDXMerge: Tool for merging multiple SPDX JSON/Tag-value SBOMs into a parent SBOM
-
Programming Languages
Categories
Sub Categories
Keywords
security
71
sbom
36
security-tools
26
supply-chain-security
25
devsecops
25
golang
24
kubernetes
22
cyclonedx
19
supply-chain
17
vulnerabilities
16
go
15
containers
15
spdx
14
python
14
docker
14
static-analysis
14
vulnerability
13
vulnerability-scanners
13
cve
13
security-automation
10
github-actions
10
compliance
10
dependencies
9
devops
9
vulnerability-detection
9
sbom-generator
8
github
8
linux
8
purl
7
open-source
7
rust
7
appsec
7
npm
7
vulnerability-management
7
software-supply-chain-security
6
software-bill-of-materials
6
security-audit
6
scanner
6
sbom-tool
6
git
5
infosec
5
vulnerability-scanner
5
malware-analysis
5
cloud-native
5
slsa
5
bill-of-materials
5
cli
5
security-scanner
5
cicd
5
cybersecurity
5