An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
-
Updated
Jul 7, 2022 - Go
{{ message }}
An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
Enabling Software Supply Chain Security Capabilities in ArgoCD
A compilation of resources in the software supply chain security domain, with emphasis on open source
A reimplementation of LastPyMile: A Python-based library to Identify the differences between build artifacts of PyPI packages and the respective source code repository
Sharing software supply chain security open source projects
Low-Code Framework to develop Microservices, REST APIs, GraphQL API, gRPC, dRPC, WebAssembly code, etc. with minimal coding and by automatically applying best practice methods like software supply chain security measures, SBOM, etc. Auto generate code after defining requirements in UI.
Add a description, image, and links to the software-supply-chain-security topic page so that developers can more easily learn about it.
To associate your repository with the software-supply-chain-security topic, visit your repo's landing page and select "manage topics."
Overview
Currently, the Phylum CLI binary is signed using minisign and the private key for Phylum. This signature can be verified using the corresponding public key for Phylum: