How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies.
Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche
Software Supply Chain Transparency Log
The main features of sigstore/rekor are: Supply Chain Security.
Open-source alternatives to sigstore/rekor include: aquasecurity/chain-bench — An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software… deislabs/ratify — Artifact Ratification Framework (CNCF Sandbox). denysvuika/supply-chain-inspector — A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies. en/code-security. grafeas/kritis — Deploy-time Policy Enforcer for Kubernetes applications. anchore/syft — Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes…