#supply-chain-security
GitHub repositories that have self-applied the topic "supply-chain-security" — a creator-tagged metadata that surfaces how AI projects describe themselves.
REPOS Repos for #supply-chain-security (top 12 by stars)
Open-source server that refuses vulnerable package installs. The backend the refuse CLI shim calls.
ralfyishere/agent-zero-trustZero-trust repo intake for AI coding agents — scan the instruction environment before Claude Code, Cursor, Codex, or Gemini touches a repo. Ships its own false-negative ledger.
MicroMilo/upstream-radarDSH plugin security and dependency monitoring for DeepSeek Harness: exact vulnerable paths, breaking updates, and Agent follow-up.
BrendenKennedy/claude-for-ai-platformsClaude Code scaffold for building AI platforms securely — agent/LLM security, Kubernetes, SRE, observability, identity, and supply chain, grounded in published framework canon (OWASP, NIST, CIS, SLSA). Data-science lanes included.
Gowrav-M/agent-skillguardPolicy-as-code admission controller for AI agent skills and MCP tools. SkillBOM, lockfiles, and supply-chain baselines.
itsraghul/lockwardenAudit what your npm dependency tree can execute — lifecycle scripts, binding.gyp, AI-agent hooks, IDE tasks — and answer "am I hit?" in seconds during supply-chain incidents. Local-first, zero telemetry.
tanrendev/jigMy Claude Code toolkit. Currently guard: hooks that scan agent-driven package installs before they run.
hamzatazeez-netizen/supply-chain-compromiseThird-party and software supply chain risk assessment of the 2026 open-source compromise wave (Trivy, Bitwarden, Checkmarx → OpenAI/Vercel downstream). Full GRC workflow: methodology, risk register, NIST CSF 2.0 / ISO 27001 / SP 800-161 control mapping, TPRM program response, KRIs, and board briefing. OSFI B-10/B-13 context.
ChrisDHolman/slopsquatMeasuring how often, and how reproducibly, LLMs hallucinate package names that don't exist — the slopsquatting supply-chain attack surface. Phase 1: detection and measurement only, read-only against PyPI/npm.
rlx/uplevelUplevel your repo's engineering process. Most tools tell you what's wrong; uplevel tells you what's missing, then hands you a ranked plan. A Claude Code skill. Nothing changes until you pick.
sho-tado/agentic-actions-guardAudit AI-agent GitHub Actions workflows for prompt-injection, token, and secret-exposure risks
avgoai/aos-workflow-gateGitHub Action + CLI for replayable CI/PR/release gate decisions - zero-config Self-Test turning checks, scanners, and AI-agent signals into deterministic, tamper-evident PASS/WARN/BLOCK records. Read-only, zero dependencies, Apache-2.0.
RELATED Other topics · full topics ranking →
#claude-code
1,555#ai-agents
1,156#llm
1,066#claude
936#python
802#ai
737#developer-tools
723#mcp
719#codex
517Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology