agent runtime security - zero trust, zero setup, zero latency.
Top SUPPLY GitHub Repositories & Tools (2026)
Discover the most starred and trending open source tools tagged with #supply.
π‘οΈ Security audit CLI for Model Context Protocol (MCP) servers β scan AI agent configs for tool poisoning, rug pulls, hardcoded secrets, command injection & supply-chain risks. Pure Python, SARIF + CI ready.
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
Go implementation of The Update Framework (TUF)
blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries.
sbomqs: The Comprehensive SBOM Quality & Compliance Tool
Artifact Ratification Framework (CNCF Sandbox)
A lightweight caching proxy for package registries.
Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.
SmuView is a GUI for sigrok that supports power supplies, electronic loads and all sorts of measurement devices like multimeters, LCR meters and so on.
A fence keeps things out, but also in. This project is still in early, and active development.
ReARM - Release Governance Platform
0-day malware detection for binaries, source & scripts (that doesn't suck)
Catalogue all images of a Kubernetes cluster to multiple targets with Syft
JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns π¬.
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
πOpen Source Security Foundation (OpenSSF) Best Practices Badge (formerly Core Infrastructure Initiative (CII) Best Practices Badge)