🔐
DevSec
💻 GitHub
  • 👋Welcome
    • DevSec
    • Glossary
    • Contributing
    • Discussions
  • 📖Resources
    • Articles
    • Books
    • Communities
    • Institutions
    • Conferences
    • Sites
    • Podcasts
    • Training
    • Other
  • ⚒️Tools
    • Static Analysis
    • Dynamic Analysis
    • Vulnerabilities Analysis
    • Dependency Management
    • Supply Chain
    • Secrets
      • Secrets Management
      • Secrets Scanning
    • Infrastructure as Code (IaC)
    • Other
  • 🔧Generic Development
    • Security Basics
    • Containers
    • Git & other VCS
    • Cryptography
  • ☁️Web Development
    • Generic
    • APIs
  • ☁️Cloud
    • Cloud native
    • Kubernetes
  • 😈On the other side
    • Red team
Powered by GitBook
On this page
  • About
  • Popular products and solutions
  • Projects
  • Other tools

Was this helpful?

Edit on GitHub
  1. Tools

Supply Chain

Keep care of your supply chain to reduce your exposure to supply chain attacks...

PreviousDependency ManagementNextSecrets

Last updated 1 year ago

Was this helpful?

About

Software supply chain security involves securing all aspects of the process of developing and delivering software, from the initial design and coding phases, through third-party components, to the end-user's system. It's about ensuring that every link in the chain is as secure as possible to prevent unauthorized access, tampering, or other malicious activities.

Popular products and solutions

From the , these tools covers "Supply Chain":

  • GitHub:

    • Supply chain security

    • Dependabot

    • GitHub Advanced Security (for orgs, enterprises or private repos)

  • Snyk:

    • Snyk Open Source (SCA)

    • Snyk Container

  • Trivy

In this section:

  • : Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript and Python dependencies.

Projects

Other tools

Sigstore ( ): a set of free to use and open source tools, handling digital signing, verification and checks for provenance needed to make it safer to distribute and use open source software.

Open Source Insights - deps.dev ( ): Open Source Insights is a service developed and hosted by Google to help developers better understand the structure, construction, and security of open source software packages.

: dependency Security Scanner that automatically notifies you about vulnerabilities.

: The definitive DevOps-centric SCA solution for identifying and resolving security vulnerabilities and license compliance issues in your open source dependencies.

: Deep scanning for real-world-risk analysis & comprehensive Software Supply Chain Security exposure discovery.

: is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity, such as email address.

: signing OCI containers (and other artifacts) using Sigstore.

: provides an immutable tamper resistant ledger of metadata generated within a software projects supply chain.

: a browser extension helping developers evaluate open source packages before picking them.

⚒️
Static Analysis section
Socket
web
web
LunaSec
JFrog Security Essentials (Xray)
JFrog Advanced Security
Fulcio
Cosign
Rekor
Overlay