This is your work, valued
awesome-software-supply-chain-security. A compilation of resources in the software supply chain security domain, with emphasis on open source
★ 373aad-login. Allows Linux user authentication to Azure AD via pam_exec
★ 51pbocker. Abstracting a pbuilder infrastructure in Docker containers
★ 3they-probably-didnt-backdoor-this-either. Learning in public about supply-chain security of community open source projects
★ 2i-probably-didnt-backdoor-this. A practical experiment on supply-chain security using reproducible builds
★ 2azpipe. A set of shims and tools for piping things to Azure
★ 2ccsirt. Crowdsourced CSIRT, focused on phishing crowdsourcing. Backend in Perl, frontend for Drupal.
★ 1azure-event-hubs-python. Python client library for Azure Event Hubs
★ 1syft. CLI tool and library for generating a Software Bill of Materials from container images and filesystems
★ 1open-cio. resources inspiring the Open CIO Series
★ 1linux-on-azure-guides. A collection of walkthroughs, scripts, guides, demos and short writes to help you get started with Linux on Azure
★ 1ZeroProof. ZeroProof — local-only network security validation for UniFi
★ 4kettle. Kettle builds and verifies attested builds, packages that include cryptographically signed SLSA provenance.
★ 35Simard. Autonomous agent acting as an engineering director across a portfolio of repositories; also a platform for building distributed autonomous agents
★ 4structured-analysis-skill. Rigorous Structured Analysis to equip Agents to Think like Intelligence Analysts
★ 57try-cli. try - fresh directories for every vibe. Your experiments deserve a home. 🏠
★ 181awesome-agent-runtime-security. Learning something new about runtime security for agents
★ 94auto-minutes. Automatic minutes generation for IETF meetings
★ 2litebox. A security-focused library OS supporting kernel- and user-mode execution
★ 2.7kmcp-server-security-standard. MCP Server Security Standard (MSSS): an open, testable security control standard for certifying MCP servers, with levels, evidence requirements, and reporting schemas.
★ 74nono. Sandbox any AI agent in seconds - zero setup, zero latency.
★ 3.3kevaluation-criteria-matrix.
★ 2saf-mcp. SAF-MCP is a comprehensive security framework for documenting and mitigating threats in the AI Agent ecosystem.
★ 353datasketch. MinHash, LSH, LSH Forest, Weighted MinHash, HyperLogLog, HyperLogLog++, LSH Ensemble and HNSW
★ 2.9ktvpo. Target, Value, Patterns and Objectives (TVPO) - A flexible threat modelling framework for the software supply chain
★ 5atlas-cli. A command-line interface tool for creating, managing, and verifying Content Provenance and Authenticity (C2PA) manifests for machine learning models, datasets, and related artifacts.
★ 22confidential-computing-cvm-guest-attestation. Confidential VM Platform Guest attestation sample apps
★ 82mcp. Catalog of official Microsoft MCP (Model Context Protocol) server implementations for AI-powered data access and tool integration
★ 3.5kdusseldorf. Dusseldorf is an out-of-band security tool to help in security research.
★ 126ccfdns. A CCF-based, attested DNS server
★ 16attested-ohttp-server. This is a rust implementation of an attested OHTTP gateway
★ 15trivy-vulnerability-explorer. Web application that allows to load a Trivy report in json format and displays the vulnerabilities of a single target in an interactive data table.
★ 178Dependency-Timeline-Audit. Dependency Timeline Audit
★ 1distro-security-meetup. Ressources for the regular meeting of distribution security teams
★ 10keylime. A CNCF Project to Bootstrap & Maintain Trust on the Edge / Cloud and IoT
★ 551hashlookup-json-importer. Generic NDJSON importer for hashlookup server
★ 3hashlookup-server. Fast lookup server for NSRL and other hash database used in digital forensic
★ 3hashlookup-forensic-analyser. Analyse a forensic target (such as a directory) to find and report files found and not found from CIRCL hashlookup public service - https://circl.lu/services/hashlookup/
★ 129image-attestation. Go
★ 6in-toto. in-toto is a framework to protect supply chain integrity.
★ 1kgrype. A vulnerability scanner for container images and filesystems
★ 13kcriticality_score. Gives criticality score for an open source project
★ 1.4ktag-security. 🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
★ 2.3kmodel-transparency. Supply chain security for ML
★ 241tac. Technical Advisory Council
★ 149rust-keylime. Rust implementation of the keylime agent
★ 161rekor. Software Supply Chain Transparency Log
★ 1.2kgo-tpm-tools. Go packages built on go-tpm providing a high-level API for using TPMs
★ 306enclave-cc. Process-based Confidential Container Runtime
★ 84draft-ietf-rats-corim. A repository to define IETF RATS Concise Reference Integrity Manifest (CoRIM) Data Format Standard for supplying Reference Values and Endorsed Values
★ 17hipcheck. Automatically assess and score software repositories for supply chain risk.
★ 126octoscan. Octoscan is a static vulnerability scanner for GitHub action workflows.
★ 272bomctl. Format agnostic SBOM tooling
★ 155formal-spec-TEE. Formal specification of attestation mechanisms in Confidential Computing
★ 24meetings. Meeting materials
★ 25snpguest. A CLI tool for interacting with SEV-SNP guest environment
★ 103sev-guest. Tools, scripts, and configuration files necessary to demonstrate an end-to-end remote attestation example with SEV-SNP.
★ 59go-sev-guest. go-sev-guest offers a library to wrap the /dev/sev-guest device in Linux, as well as a library for attestation verification of fundamental components of an attestation report.
★ 76trustee. Attestation and Secret Delivery Components
★ 170C2SP. Community Cryptography Specification Project
★ 642ast-grep-essentials. Community-led collection of essential ast-grep rules.
★ 143goatrodeo. Deep Inspection - Artifact Dependency Graph
★ 6omnibor-rs. Rust implementation of OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.
★ 30specification.
★ 87azure-privacy-sandbox-kms. TypeScript
★ 13CCF. Confidential Consortium Framework
★ 870scitt-ccf-ledger. Supply Chain Integrity Transparency and Trust ledger application using Confidential Consortium Framework (CCF)
★ 45osim. OASIS OSIM TC: Working directory for OSIM TC
★ 5transparency-exchange-api. A standard API specification for exchanging supply chain artifacts and intelligence
★ 110ai-ml-security. Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
★ 183what-the-src. Source code of https://whatsrc.org/
★ 49chainloop. SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
★ 570protobom. A universal SBOM representation in protocol buffers
★ 326sealed-secrets. A Kubernetes controller and tool for one-way encrypted Secrets
★ 9.2kkubesec. Security risk analysis for Kubernetes resources
★ 1.5kbeyla. eBPF-based autoinstrumentation of web applications and network metrics
★ 2.1kpackage-analysis. Open Source Package Analysis
★ 903wg-best-practices-os-developers. The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
★ 1.1kblueprint-securesoftwarepipeline. For engineers and security teams driving fast and secure software supply chains
★ 87overlay. Overlay is a browser extension helping developers evaluate open source packages before picking them
★ 229copacetic. 🧵 CLI tool for directly patching container images!
★ 1.7kopenssl-nov-1-critical-cve-2022-tracking.
★ 8hpsm. Go
★ 4annotate-registry-artifacts. CLI for adding OCI annotations to existing registry artifacts
★ 7image-layer-provenance. Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.
★ 45SecureSoftwareSupplyChain. This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.
★ 140unlocker. ⚠️ Replaced by ItalyPaleAle/Revaulter! -- Wrap and unwrap keys using a key vault with admin consent
★ 8oss-ssc-framework. Open Source Software Secure Supply Chain Framework
★ 238OSSGadget. Collection of tools for analyzing open source packages.
★ 370dotnet. Ubuntu ROCKs for the .NET runtime and family
★ 53chisel. Go
★ 413omega-stracedb. A repository of strace results for lots of packages.
★ 2template-analyzer. Template scanner for security misconfiguration and best practices
★ 143security-devops-action. Microsoft Security DevOps for GitHub Actions.
★ 160Microsoft-Defender-for-Cloud. Welcome to the Microsoft Defender for Cloud community repository
★ 1.9ksbom-tool. The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.
★ 2.1kDevSkim. DevSkim is a set of IDE plugins, language analyzers, and rules that provide security "linting" capabilities.
★ 1kdraft-birkholz-scitt-architecture. A specification including, problem statement, use cases, requirements, and architectural constituents for a Transparency Service in support of Supply Chain Integrity, Transparency, and Trust
★ 14zas. Most simple static website generator in Golang.
★ 215linux-package-repositories. Microsoft Packaged Linux Software (DEBs, RPMs, etc) are hosted on packages.microsoft.com (PMC) made available as native Linux repositories for use with package managers like APT, YUM, etc.
★ 118awesome-software-supply-chain-security. A compilation of resources in the software supply chain security domain, with emphasis on open source
★ 373gardenlinux. Garden Linux - The best Linux for Gardener nodes!
★ 224slsa. Supply-chain Levels for Software Artifacts
★ 1.9kossf-landscape.
★ 32witness. Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
★ 539debrebuild. Given a buildinfo file from a Debian package, generate instructions for attempting to reproduce the binary packages built from the associated source and build information.
★ 17supply-chain-synthesis. Collating an overview of the open source software supply chain landscape -- and synthesizing that survey in a hopefully-useful way.
★ 35wg-securing-critical-projects. Helping allocate resources to secure the critical open source projects we all depend on.
★ 403component-detection. Scans your project to determine what components you use
★ 545azure-osconfig. A modular services stack that facilitates remote Linux devices management over Azure
★ 35ratify. Artifact Ratification Framework (CNCF Sandbox)
★ 307security-reviews. A community collection of security reviews of open source software components.
★ 100wsl2-systemd. Enable basic systemd service management support for WSL2
★ 8LinuxPatchExtension. Microsoft Azure VM Guest Linux Patch Extension
★ 12apt-transport-cloudflared.
★ 1apt-transport-oci. OCI transport plugin for apt-get (i.e., apt-get over ghcr.io)
★ 119package-metadata. A place to collect information about packages across various ecosystems
★ 3syft. CLI tool and library for generating a Software Bill of Materials from container images and filesystems
★ 9.3kspdx-oin. SPDX documents and related code for OIN's Linux System Definition packages
★ 1spdx-sbom-generator. Support CI generation of SBOMs via golang tooling.
★ 427scim. Supply Chain Integrity Model
★ 108cyclonedx-linux-generator. Lockheed Martin developed utility to generate CycloneDX SBOMs for Linux distributions
★ 55kubernetes-workshop. ⚙️ A Gentle introduction to Kubernetes with more than just the basics. 🌟 Give it a star if you like it.
★ 3.2kakri. A Kubernetes Resource Interface for the Edge
★ 1.3kwaypoint. A tool to build, deploy, and release any application on any platform.
★ 4.7kwhatfiles. Log what files are accessed by any Linux process
★ 946percollate. A command-line tool to turn web pages into readable PDF, EPUB, HTML, or Markdown docs.
★ 4.7kwg-security-tooling. OpenSSF Security Tooling Working Group
★ 326wg-supply-chain-integrity. Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
★ 207opensource.microsoft.com. This is the source code to the mostly-static Microsoft Open Source site featuring projects, program information, and "get involved" pages.
★ 1.1kazurelinux. General purpose Linux OS for Azure
★ 5.3kCloudShell. Container Image for Azure Cloud Shell (https://azure.microsoft.com/en-us/features/cloud-shell/)
★ 273decentralized-identity.github.io. Site for the open source, community-driven group of dev and organizations working toward an interoperable, decentralized identity ecosystem
★ 111azvmimagebuilder. Azure VM Image Builder
★ 184choose. A human-friendly and fast alternative to cut (and sometimes awk)
★ 2.3koneinfra. Kubernetes as a Service
★ 876InnerSourcePatterns. These patterns document how to apply open source principles and practices for software development within the confines of an organization - aka InnerSource.
★ 850sidetree. Sidetree Specification and Reference Implementation
★ 439linux-observability-with-bpf. Code snippets from the O'Reilly book
★ 928sgx-lkl. SGX-LKL Library OS for running Linux applications inside of Intel SGX enclaves
★ 269Azure-Readiness-Checklist. This checklist is your guide to the best practices for deploying secure, scalable, and highly available infrastructure in Azure. Before you go live, go through each item, and make sure you haven't missed anything important!
★ 498distri. a Linux distribution to research fast package management
★ 553deb-ostree-builder. Stripped down Endless ostree builder for debian
★ 68dnote. A simple command line notebook
★ 3kwebsocketd. Turn any program that uses STDIN/STDOUT into a WebSocket server. Like inetd, but for WebSockets.
★ 17krest-fs. REST API FUSE filesystem experiment
★ 20debos. Debian OS builder
★ 720build-your-own-radar. A library that generates an interactive radar, inspired by https://thoughtworks.com/radar/.
★ 2.6kmdCanvas. Create a Lean Canvas out of a markdown list
★ 13blog. Aquí está el código original de los artículos publicados en programar.cloud
★ 6sidedoor. SSH connection daemon for Debian/Raspbian/Ubuntu/etc
★ 129dcos-kafka-cassandra. Python
★ 6sysunconfig.
★ 2awesome-sysadmin. A curated list of amazingly awesome open source sysadmin resources inspired by Awesome PHP.
★ 24kfpi. no longer needed because snaps are a thing
★ 18azure-service-broker-client. Java
★ 7ansible-azure-lab. Lab to play with Azure using Ansible playbooks
★ 73MicrosoftDevOps.github.io. Repository of the Microsoft DevOps Evidences
★ 12docker-and-containers-ebooks. A series of ebooks on Docker and the container ecosystem.
★ 837AzureRunMe. Runs third party technologies on Windows Azure
★ 42autorest. OpenAPI (f.k.a Swagger) Specification code generator. Supports C#, PowerShell, Go, Java, Node.js, TypeScript, Python
★ 4.8kconnectthedots. Connect tiny devices to Microsoft Azure services to build IoT solutions
★ 396azure-linux. Documentation and examples for how to leverage various linux technologies with Azure
★ 62azpipe. A set of shims and tools for piping things to Azure
★ 2aguilas. [ARCHIVED] A web-based LDAP user management system written in PHP.
★ 14