AI Dev Impact Lab JA
← Topics ranking · 2026-08
GITHUB TOPIC

#supply-chain-security

GitHub repositories that have self-applied the topic "supply-chain-security" — a creator-tagged metadata that surfaces how AI projects describe themselves.

12
tagged repos
19
top 12 stars
5
with tool sigs
12
shown

REPOS Repos for #supply-chain-security (top 12 by stars)

RefuseHQ/refuse

Open-source server that refuses vulnerable package installs. The backend the refuse CLI shim calls.

TypeScript 10 AI 45 live ↗
ralfyishere/agent-zero-trust

Zero-trust repo intake for AI coding agents — scan the instruction environment before Claude Code, Cursor, Codex, or Gemini touches a repo. Ships its own false-negative ledger.

Python 4 AI 100
MicroMilo/upstream-radar

DSH plugin security and dependency monitoring for DeepSeek Harness: exact vulnerable paths, breaking updates, and Agent follow-up.

TypeScript 4 AI 70 Solo 1 sig live ↗
BrendenKennedy/claude-for-ai-platforms

Claude Code scaffold for building AI platforms securely — agent/LLM security, Kubernetes, SRE, observability, identity, and supply chain, grounded in published framework canon (OWASP, NIST, CIS, SLSA). Data-science lanes included.

Shell 1 AI 100 1 sig
Gowrav-M/agent-skillguard

Policy-as-code admission controller for AI agent skills and MCP tools. SkillBOM, lockfiles, and supply-chain baselines.

TypeScript 0 AI 100
itsraghul/lockwarden

Audit what your npm dependency tree can execute — lifecycle scripts, binding.gyp, AI-agent hooks, IDE tasks — and answer "am I hit?" in seconds during supply-chain incidents. Local-first, zero telemetry.

TypeScript 0 AI 70 Solo 1 sig live ↗
tanrendev/jig

My Claude Code toolkit. Currently guard: hooks that scan agent-driven package installs before they run.

Python 0 AI 70 1 sig
hamzatazeez-netizen/supply-chain-compromise

Third-party and software supply chain risk assessment of the 2026 open-source compromise wave (Trivy, Bitwarden, Checkmarx → OpenAI/Vercel downstream). Full GRC workflow: methodology, risk register, NIST CSF 2.0 / ISO 27001 / SP 800-161 control mapping, TPRM program response, KRIs, and board briefing. OSFI B-10/B-13 context.

0 AI 70 live ↗
ChrisDHolman/slopsquat

Measuring how often, and how reproducibly, LLMs hallucinate package names that don't exist — the slopsquatting supply-chain attack surface. Phase 1: detection and measurement only, read-only against PyPI/npm.

Python 0 AI 70
rlx/uplevel

Uplevel your repo's engineering process. Most tools tell you what's wrong; uplevel tells you what's missing, then hands you a ranked plan. A Claude Code skill. Nothing changes until you pick.

Shell 0 AI 70 1 sig
sho-tado/agentic-actions-guard

Audit AI-agent GitHub Actions workflows for prompt-injection, token, and secret-exposure risks

Python 0 AI 60 Solo live ↗
avgoai/aos-workflow-gate

GitHub Action + CLI for replayable CI/PR/release gate decisions - zero-config Self-Test turning checks, scanners, and AI-agent signals into deterministic, tamper-evident PASS/WARN/BLOCK records. Read-only, zero dependencies, Apache-2.0.

Python 0 AI 60

RELATED Other topics · full topics ranking →

#claude-code

1,555

#ai-agents

1,156

#llm

1,066

#claude

936

#python

802

#ai

737

#developer-tools

723

#mcp

719

#codex

517

Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology