supply-chain-security — independent software & tools
-
clauderabbit
ClaudeRabbit is a free, open-source security product protecting the open-source community from malware. We clone any public GitHub repo into an isolated sandbox, run it, and return one honest safety score.
-
targate
AI-assisted pre-install security gate for npm packages — analyze, decide, and gate a dependency before it runs.
-
trusca
Self-hosted, open-source SCA portal — vulnerability (CVE), license compliance, and SBOM management in one UI. Black Duck/Snyk-class capabilities, Apache-2.0.
-
lopper
measure dependency waste and attack surface before it ships
-
franken_node
Trust-native JavaScript/TypeScript runtime platform built on franken_engine with deterministic compatibility, migration autopilot, extension trust controls, and incident replay.
-
gradle-wrapper-validator
A validator for gradle/wrapper jar binaries, intended to be used in CI pipelines.
-
gh-actions-lock
A gh CLI extension that generates and verifies the GitHub Actions dependency lockfile, pinning every action your workflows use to an exact commit.
-
starmetal
High-performance, self-hosted multi-language package registry and registry proxy
-
nthpartyfinder
Discover Nth-party vendor relationships (3rd, 4th, and deeper) for a domain from public signals — DNS, certificate transparency, trust-center subprocessors, web traffic, and more. A fast, offline-capable GRC Engineering CLI in Rust.