A compilation of resources in the software supply chain security domain, with emphasis on open source
-
Updated
Apr 24, 2023
A compilation of resources in the software supply chain security domain, with emphasis on open source
Split and distribute your private keys securely amongst untrusted network
List your dependencies capabilities and monitor if updates require more capabilities.
A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.
Packj audits pull requests for malicious/risky open-source deps
Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574
New Android supply chain attack surface
Compute SRI from an HTML file and generate a new HTML with the integrity attribute.
Python script to check if any malicious pip packages listed in a text file have been installed.
Add a description, image, and links to the supply-chain-attacks topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain-attacks topic, visit your repo's landing page and select "manage topics."