Go supply-chain-security

Open-source Go projects categorized as supply-chain-security

Top 11 Go supply-chain-security Projects

supply-chain-security
  1. guac

    GUAC aggregates software security metadata into a high fidelity graph database.

  2. InfluxDB

    InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.

    InfluxDB logo
  3. legitify

    Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

  4. minefield

    Graphing SBOM's Fast.

    Project mention: Show HN: Minefield – Fast SBoM Management, 10k Packages Cached in 30s | news.ycombinator.com | 2024-09-06
  5. vet

    Next Generation Software Composition Analysis (SCA) with Malicious Package Detection, Code Context & Policy as Code

    Project mention: Ask HN: What Are You Working On? (June 2025) | news.ycombinator.com | 2025-06-29

    I am working on a next-gen software composition analysis tool that can identify malicious open source packages through code analysis. Adopts a policy as code (CEL) approach to build security guardrails against risky OSS components using opinionated policies.

    GitHub: https://github.com/safedep/vet

  6. chainloop

    Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

  7. bsf

    Developer-centric tool to secure your software supply chain. (by buildsafedev)

    Project mention: Show HN: BuildSafe – Build 0 CVE base images with ease | news.ycombinator.com | 2024-08-23
  8. secure-repo

    Orchestrate GitHub Actions Security

  9. Stream

    Stream - Scalable APIs for Chat, Feeds, Moderation, & Video. Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure.

    Stream logo
  10. SBOM Quality Score

    SBOM Assess - Evaluate SBOM quality and compliance

  11. sbom-operator

    Catalogue all images of a Kubernetes cluster to multiple targets with Syft

  12. pmg

    PMG protects developers from getting compromised by malicious packages

    Project mention: PMG: Wraps Package Managers to Prevent Installation of Malicious OSS Packages | news.ycombinator.com | 2025-05-15
  13. solarsploit

    Red team tool that emulates the SolarWinds CI compromise attack vector.

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Go supply-chain-security discussion

Log in or Post with

Go supply-chain-security related posts

  • Vet MCP: Software Composition Analysis for AI Code Editors

    1 project | news.ycombinator.com | 6 Jun 2025
  • Malicious npm Package Impersonating Popular Express Cookie Parser

    2 projects | dev.to | 27 May 2025
  • How to Effectively Vet Your Supply Chain for Optimal Performance

    2 projects | dev.to | 15 May 2025
  • Ask HN: How are you acquiring first 100 users?

    2 projects | news.ycombinator.com | 13 May 2025
  • Show HN: MCP-Shield – Detects security issues in MCP servers

    5 projects | news.ycombinator.com | 14 Apr 2025
  • Agentic Analysis of Open Source Package Code for Malware

    1 project | dev.to | 8 Apr 2025
  • Show HN: Scan GitHub Actions for Malicious Code

    1 project | news.ycombinator.com | 20 Mar 2025
  • A note from our sponsor - Stream
    getstream.io | 12 Jul 2025
    Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure. Learn more →

Index

What are some of the best open-source supply-chain-security projects in Go? This list will help you:

# Project Stars
1 guac 1,381
2 legitify 812
3 minefield 724
4 vet 523
5 chainloop 474
6 bsf 290
7 secure-repo 291
8 SBOM Quality Score 220
9 sbom-operator 202
10 pmg 34
11 solarsploit 24

Sponsored
InfluxDB – Built for High-Performance Time Series Workloads
InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
www.influxdata.com