<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>supply-chain</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/974/feed"/>
    <updated>2026-09-15T13:41:43+00:00</updated>
    <id>https://links.biapy.com/guest/tags/974/feed</id>
            <entry>
            <id>https://links.biapy.com/links/13890</id>
            <title type="text"><![CDATA[Drydock Package Review]]></title>
            <link rel="alternate" href="https://drydock.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13890"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Review the package artifact before it ships. pre-publish package security.
Review the artifact before you publish it: diffs the built npm/PyPI package against the last published version and pins risk signals to the changed lines.

Between your last code review and the public registry sit build scripts, bundler output, and CI credentials. Drydock diffs the exact artifact against the last published version and pins every supply-chain finding to a changed line. Workflow Gate enforces the decision on a configured protected job; Stage Watchtower records an advisory npm review.

- [Drydock @ GitHub](https://github.com/JoviDeCroock/drydock).]]>
            </summary>
            <updated>2026-09-14T05:48:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13771</id>
            <title type="text"><![CDATA[DecryptAds]]></title>
            <link rel="alternate" href="https://decryptads.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13771"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[From Hidden Flows to Public Insight.

 DecryptAds is a programmatic supply chain transparency platform built by Svart Works Inc. We map ads.txt, app-ads.txt, sellers.json, buyers.json, and adagents.json; surface risk across publishers, data brokers, and ad tech intermediaries; and give researchers, operators, and the public tools to investigate what is really happening behind the bid stream. 

Related contents:

- [Who’s Tracking You? Use This New Service to Find Out @ KrebsonSecurity](https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/).]]>
            </summary>
            <updated>2026-09-03T18:53:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13693</id>
            <title type="text"><![CDATA[Deputy]]></title>
            <link rel="alternate" href="https://github.com/temporalio/deputy" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13693"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Deputy enables dependency management at scale.

Deputy aims to provide core dependency management primitives along with a unified toolchain, so you can focus on what matters: your code and policies that protect it. The tool is designed for extensibility, performance, and usability at scale; whether you’re an individual developer, a security team, or an enterprise organization. The goal is to empower you to manage dependencies effectively, reduce risk, and maintain a secure software supply chain with minimal friction.

Related contents:

- [Introducing Deputy: Better signal and control for software supply chains @ Temporal](https://temporal.io/blog/introducing-deputy).]]>
            </summary>
            <updated>2026-08-20T12:13:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13667</id>
            <title type="text"><![CDATA[Varnish Orca Artifact Firewall]]></title>
            <link rel="alternate" href="https://www.varnish-software.com/products/software-supply-chain/varnish-artifact-firewall/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13667"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Varnish Orca is a Virtual Registry Manager: a fast pull-through cache for artifact registries.
Control which packages reach your developers, pipelines, and agents.

Deploy it close to your developers and CI/CD pipelines to reduce build times and egress costs.

- [Varnish Orca @ GitHub](https://github.com/varnish/orca).

Related contents:

- [Varnish Artifact Firewall : contrôler l&amp;#039;entrée des dépendances @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/supply-chain/artifact-firewall/).]]>
            </summary>
            <updated>2026-08-17T09:26:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13443</id>
            <title type="text"><![CDATA[Let&amp;#039;s Seal]]></title>
            <link rel="alternate" href="https://letsseal.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13443"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[the open standard for sealing anything.

The open standard for proving any file is real, unaltered, sealed by a known certificate, and in existence by a certain date. One standard for every kind of file: documents, images, email, code, containers. Verifiable by anyone, forever. The proof travels with the file and stands on its own.

- [Let&amp;#039;s Seal @ GitHub](https://github.com/letsseal/letsseal).]]>
            </summary>
            <updated>2026-07-28T12:28:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13328</id>
            <title type="text"><![CDATA[Bumblebee Hive]]></title>
            <link rel="alternate" href="https://github.com/radioactivetobi/bumblebee-hive" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13328"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fleet visibility dashboard and ingest server for Bumblebee scans.

Run the Hive server, point developer endpoints at it with --output http, and browse fleet inventory, exposure findings, and per-endpoint scan history in a React dashboard — no log shipper or custom receiver required.

 Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.]]>
            </summary>
            <updated>2026-07-20T04:57:05+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13246</id>
            <title type="text"><![CDATA[gh-workflow-hardener]]></title>
            <link rel="alternate" href="https://github.com/indoor47/gh-workflow-hardener" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13246"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[GitHub Actions security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities. 

Secure your GitHub Actions workflows against supply chain attacks. Detects unpinned actions (the tj-actions attack vector), dangerous permissions, and script injection — all in one scan.]]>
            </summary>
            <updated>2026-07-09T07:00:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13237</id>
            <title type="text"><![CDATA[replacements.fyi]]></title>
            <link rel="alternate" href="https://replacements.fyi/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13237"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[performant, safer npm package alternatives.

type a package name. we&amp;#039;ll tell you what you don&amp;#039;t need.
The module replacements project is a community-driven effort to map replaceable npm packages to their native or more performant alternatives.

This website serves as a searchable, interactive catalog of these module replacements, allowing you to easily find and adopt better alternatives for your projects.

- [replacements.fyi @ GitHub](https://github.com/e18e/replacements.fyi).

Related contents:

- [\#1014 - Anthropic doesn’t use AI @ Syntax](https://syntax.fm/show/1014/anthropic-doesn-t-use-ai).]]>
            </summary>
            <updated>2026-07-07T05:49:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12921</id>
            <title type="text"><![CDATA[cicd-sensor]]></title>
            <link rel="alternate" href="https://cicd-sensor.github.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12921"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Think EDR, but for CI/CD Pipelines.
Open-source eBPF-powered runtime security sensor for GitHub Actions and GitLab CI/CD.

- [cicd-sensor @ GitHub](https://github.com/cicd-sensor/cicd-sensor).]]>
            </summary>
            <updated>2026-06-04T13:09:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12878</id>
            <title type="text"><![CDATA[git-pkgs proxy]]></title>
            <link rel="alternate" href="https://github.com/git-pkgs/proxy" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12878"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A lightweight caching proxy for package registries.

A caching proxy for package registries. Speeds up package downloads by caching artifacts locally, reducing bandwidth usage and improving reliability.]]>
            </summary>
            <updated>2026-06-01T15:52:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12703</id>
            <title type="text"><![CDATA[Dependency Cooldowns]]></title>
            <link rel="alternate" href="https://cooldowns.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12703"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🛡️ Dependency cooldowns are cool! 

- [Dependency Cooldowns @ GitHub](https://github.com/mprpic/cooldowns).]]>
            </summary>
            <updated>2026-05-14T14:15:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12656</id>
            <title type="text"><![CDATA[Fork Commit Detector]]></title>
            <link rel="alternate" href="https://ramimac.me/imposter/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12656"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Detect potential imposter commits in GitHub repositories]]>
            </summary>
            <updated>2026-04-30T11:19:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12649</id>
            <title type="text"><![CDATA[Package Manager Guard (PMG)]]></title>
            <link rel="alternate" href="https://github.com/safedep/pmg" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12649"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep&amp;#039;s threat intelligence feed. 

PMG intercepts every package install and checks it for malware before code executes. Install it once, and every npm install, pip install, and poetry add is protected automatically.]]>
            </summary>
            <updated>2026-04-29T14:21:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12554</id>
            <title type="text"><![CDATA[Supply Chain Monitor]]></title>
            <link rel="alternate" href="https://github.com/elastic/supply-chain-monitor" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12554"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated monitoring of the top PyPI and npm packages for supply chain compromise. Polls both registries for new releases, diffs each release against its predecessor, and uses an LLM (via Cursor Agent CLI) to classify diffs as benign or malicious. Malicious findings trigger a Slack alert.

Related contents:

- [\#72 - Microsoft et Adobe corrigent une vulnérabilité déjà exploitée @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-72-microsoft-et-adobe-corrigent-une-vuln-rabilit-d-j-exploit-e).]]>
            </summary>
            <updated>2026-04-16T11:38:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11994</id>
            <title type="text"><![CDATA[git-pkgs]]></title>
            <link rel="alternate" href="https://git-pkgs.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11994"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Dependency tools for git

A git subcommand that indexes your dependency changes into a queryable database. 
Find out who added a package, when, and why.

- [git-pkgs @ GitHub](https://github.com/git-pkgs/git-pkgs).

Related contents:

- [Git&amp;#039;s Magic Files @ Andrew Nesbitt](https://nesbitt.io/2026/02/05/git-magic-files.html).]]>
            </summary>
            <updated>2026-03-03T12:59:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11746</id>
            <title type="text"><![CDATA[SITF]]></title>
            <link rel="alternate" href="https://wiz-sec-public.github.io/SITF/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11746"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SDLC Infrastructure Threat Framework

A comprehensive framework for understanding and mitigating supply chain security threats across the Software Development Lifecycle infrastructure. 

- [SITF @ GitHub](https://github.com/wiz-sec-public/SITF).

Related contents:

- [Introducing SITF: The First Threat Framework Dedicated to SDLC Infrastructure @ Wiz](https://www.wiz.io/blog/sitf-sdlc-threat-framework).]]>
            </summary>
            <updated>2026-02-09T06:31:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11237</id>
            <title type="text"><![CDATA[OpenSSF Scorecard]]></title>
            <link rel="alternate" href="https://scorecard.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11237"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Build better security habits, one test at a time.
Quickly assess open source projects for risky practices.

- [OpenSSF Scorecard @ GitHub](https://github.com/ossf/scorecard).

Related contents:

- [OpenSSF Scorecard @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/supply-chain/scorecard/).]]>
            </summary>
            <updated>2025-12-15T09:57:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11172</id>
            <title type="text"><![CDATA[pinact]]></title>
            <link rel="alternate" href="https://github.com/suzuki-shunsuke/pinact" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11172"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[pinact is a CLI to edit GitHub Workflow and Composite action files and pin versions of Actions and Reusable Workflows. pinact can also update their versions and verify version annotations.]]>
            </summary>
            <updated>2025-12-05T15:21:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10675</id>
            <title type="text"><![CDATA[npq]]></title>
            <link rel="alternate" href="https://github.com/lirantal/npq" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10675"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[safely install npm packages by auditing them pre-install stage.
npq allows you to audit npm packages before you install them.

Related contents:

- [\#121 - Les news Web Dev d’octobre 2025. Adonis, Laravel, React Compiler, Vite+ et bien plus encore ! @ Double Slash :fr:](https://double-slash.dev/podcasts/news-oct25/).]]>
            </summary>
            <updated>2025-10-16T06:36:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10647</id>
            <title type="text"><![CDATA[CycloneDX]]></title>
            <link rel="alternate" href="https://cyclonedx.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10647"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CycloneDX Bill of Materials Standard.

CycloneDX is a modern standard for the software supply chain.

The International Standard for Bill of Materials (ECMA-424)
The OWASP Foundation and Ecma International Technical Committee for Software &amp;amp; System Transparency (TC54) drive the continued advancement of the specification.

- [CycloneDX BOM Standard @ GitHub](https://github.com/CycloneDX).

Related contents:

- [CycloneDX PHP Composer Plugin @ GitHub](https://github.com/CycloneDX/cyclonedx-php-composer).]]>
            </summary>
            <updated>2025-10-14T09:44:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10451</id>
            <title type="text"><![CDATA[NPM Supply Chain Security Scanner]]></title>
            <link rel="alternate" href="https://github.com/Drasrax/npm-shai-hulud-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10451"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Comprehensive detection tool for NPM supply chain attacks, specifically designed to identify and prevent the Shai-Hulud worm that compromised 500+ packages including CrowdStrike npm packages in 2025. 

Related contents:

- [Malicious NPM packages: Are you exposed? @ sysdig](https://www.sysdig.com/blog/malicious-npm-packages-are-you-exposed).
- [Un scanner pour lutter contre l&amp;#039;attaque Shai-Hulud @ Korben :fr:](https://korben.info/npm-shai-hulud-scanner-attaque-supply-chain.html).]]>
            </summary>
            <updated>2025-09-29T13:04:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10368</id>
            <title type="text"><![CDATA[NPM Security Best Practices]]></title>
            <link rel="alternate" href="https://github.com/bodadotsh/npm-security-best-practices" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10368"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[How to stay safe from NPM supply chain attacks.

The NPM ecosystem is no stranger to compromises, supply-chain attacks, malware, spam, phishing, incidents, or even trolls. In this repository, I have consolidated a list of information you might find useful in securing yourself against these incidents.]]>
            </summary>
            <updated>2025-09-23T11:37:14+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1029</id>
            <title type="text"><![CDATA[OpenSSF Scorecard]]></title>
            <link rel="alternate" href="https://openssf.org/projects/scorecard/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1029"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OpenSSF Scorecard assesses open source projects for security risks through a series of automated checksIt was created by OSS developers to help improve the health of critical projects that the community depends on.

You can use it to proactively assess and make informed decisions about accepting security risks within your codebase. You can also use the tool to evaluate other projects and dependencies, and work with maintainers to improve codebases you might want to integrate.

Scorecard is an automated tool that assesses a number of important heuristics (&amp;quot;checks&amp;quot;) associated with software security and assigns each check a score of 0-10. You can use these scores to understand specific areas to improve in order to strengthen the security posture of your project. You can also assess the risks that dependencies introduce, and make informed decisions about accepting these risks, evaluating alternative solutions, or working with the maintainers to make improvements.

- [OpenSSF Scorecard @ GitHub](https://github.com/ossf/scorecard).

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-28T18:48:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1030</id>
            <title type="text"><![CDATA[Package Analysis – Open Source Security Foundation]]></title>
            <link rel="alternate" href="https://openssf.org/package-analysis/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1030"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Package Analysis project analyses the capabilities of packages available on open source repositories. The project looks for behaviors that indicate malicious software:

- What files do they access?
- What addresses do they connect to?
- What commands do they run?

- [Package Feeds @ GitHub](https://github.com/ossf/package-feeds).

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-28T18:48:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1031</id>
            <title type="text"><![CDATA[in-toto]]></title>
            <link rel="alternate" href="https://in-toto.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1031"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A framework to secure the integrity of software supply chains.

in-toto is designed to ensure the integrity of a software product from initiation to end-user installation. It does so by making it transparent to the user what steps were performed, by whom and in what order.

- [in-toto](https://in-toto.github.io/).
- [in-toto @ GitHub](https://github.com/in-toto/in-toto).

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).
- [Secure publication of Datadog Agent integrations with TUF and in-toto @ Datadog](https://www.datadoghq.com/blog/engineering/secure-publication-of-datadog-agent-integrations-with-tuf-and-in-toto/).]]>
            </summary>
            <updated>2025-08-28T18:48:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1032</id>
            <title type="text"><![CDATA[Supply-Chain Firewall]]></title>
            <link rel="alternate" href="https://github.com/DataDog/supply-chain-firewall/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1032"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A tool for preventing the installation of malicious PyPI and npm packages 🔥.

Supply-Chain Firewall is a command-line tool for preventing the installation of malicious PyPI and npm packages. It is intended primarily for use by engineers to protect their development workstations from compromise in a supply-chain attack.

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-28T18:48:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1034</id>
            <title type="text"><![CDATA[GuardDog]]></title>
            <link rel="alternate" href="https://github.com/DataDog/guarddog" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1034"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages.

GuardDog is a CLI tool that allows to identify malicious PyPI and npm packages or Go modules. It runs a set of heuristics on the package source code (through Semgrep rules) and on the package metadata.
GuardDog can be used to scan local or remote PyPI and npm packages or Go modules using any of the available heuristics.

Related contents:

- [Finding malicious PyPI packages through static code analysis: Meet GuardDog @ Datadog Security Labs](https://securitylabs.datadoghq.com/articles/guarddog-identify-malicious-pypi-packages/).
- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-28T18:50:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3163</id>
            <title type="text"><![CDATA[s3cme]]></title>
            <link rel="alternate" href="https://github.com/mchmarny/s3cme" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3163"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sample Go app repo with test and release pipelines optimized for software supply chain security (S3C).

 Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance]]>
            </summary>
            <updated>2025-08-29T00:44:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3222</id>
            <title type="text"><![CDATA[Cosign]]></title>
            <link rel="alternate" href="https://github.com/sigstore/cosign" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3222"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Code signing and transparency for containers and binaries.
Signing OCI containers (and other artifacts) using Sigstore!
Cosign aims to make signatures invisible infrastructure.

Related contents:

- [Sécuriser la Supply Chain avec Cosign @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/supply-chain/cosign/).
- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-29T00:53:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3284</id>
            <title type="text"><![CDATA[KubeClarity]]></title>
            <link rel="alternate" href="https://github.com/openclarity/kubeclarity" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3284"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems. It scans both runtime K8s clusters and CI/CD pipelines for enhanced software supply chain security.]]>
            </summary>
            <updated>2025-08-29T01:04:50+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3618</id>
            <title type="text"><![CDATA[Sigstore]]></title>
            <link rel="alternate" href="https://www.sigstore.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3618"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sigstore is an open source project for improving software supply chain security. The Sigstore framework and tooling empowers software developers and consumers to securely sign and verify software artifacts such as release files, container images, binaries, software bills of materials (SBOMs), and more. Signatures are generated with ephemeral signing keys so there’s no need to manage keys. Signing events are recorded in a tamper-resistant public log so software developers can audit signing events.

- [Sigstore @ GitHub](https://github.com/sigstore/sigstore).
- [Sigstore documentation](https://docs.sigstore.dev/).

Related contents:

- [Streamline security with keyless signing and verification in GitLab @ GitLab](https://about.gitlab.com/blog/2023/09/13/keyless-signing-with-cosign/).
- [Annotate container images with build provenance using Cosign in GitLab CI/CD @ GitLab](https://about.gitlab.com/blog/2024/09/04/annotate-container-images-with-build-provenance-using-cosign-in-gitlab-ci-cd/).
- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).
- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).]]>
            </summary>
            <updated>2026-02-18T13:13:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4043</id>
            <title type="text"><![CDATA[OWASP Dependency-Check]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-dependency-check/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4043"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Dependency-Check is a Software Composition Analysis (SCA) tool that attempts to detect publicly disclosed vulnerabilities contained within a project’s dependencies. It does this by determining if there is a Common Platform Enumeration (CPE) identifier for a given dependency. If found, it will generate a report linking to the associated CVE entries.

- [Dependency-Check @ GitHub](https://github.com/dependency-check/DependencyCheck).]]>
            </summary>
            <updated>2025-08-29T03:10:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4255</id>
            <title type="text"><![CDATA[libyear]]></title>
            <link rel="alternate" href="https://libyear.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4255"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A simple measure of software dependency freshness. It is a single number telling you how up-to-date your dependencies are.]]>
            </summary>
            <updated>2025-08-29T03:46:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5498</id>
            <title type="text"><![CDATA[SLSA]]></title>
            <link rel="alternate" href="https://slsa.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5498"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Supply-chain Levels for Software Artifacts, or SLSA (&amp;quot;salsa&amp;quot;).

SLSA is a specification for describing and incrementally improving supply chain security, established by industry consensus. It is organized into a series of levels that describe increasing security guarantees.

It’s a security framework, a checklist of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure. It’s how you get from &amp;quot;safe enough&amp;quot; to being as resilient as possible, at any link in the chain.

- [SLSA @ GitHub](https://github.com/slsa-framework/slsa).

Related contents:

- [Securing the software supply chain with the SLSA framework @ Trail of Bits Blog](https://blog.trailofbits.com/2024/10/01/securing-the-software-supply-chain-with-the-slsa-framework/).
- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).
- [Kube-Policies BinauthZ: Closing the Supply Chain Gap in Kubernetes @ Block Engineering Blog](https://engineering.block.xyz/blog/kube-policies-binauthz-closing-the-supply-chain-gap-in-kubernetes).]]>
            </summary>
            <updated>2026-02-09T06:25:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5545</id>
            <title type="text"><![CDATA[Open Source Insights]]></title>
            <link rel="alternate" href="https://deps.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5545"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Open Source Insights page for each package shows the full dependency graph and updates it every day. The information provided can help you make informed decisions about using, building, and maintaining your software.

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-29T07:21:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5633</id>
            <title type="text"><![CDATA[Socket]]></title>
            <link rel="alternate" href="https://socket.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5633"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secure your supply chain. Ship with confidence.
Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript and Python dependencies.

-  [Socket @ GitHub](https://github.com/SocketDev).

Related contents:

- [Introducing Socket Firewall: Free, Proactive Protection for Your Software Supply Chain @ Socket](https://socket.dev/blog/introducing-socket-firewall).
- [\#121 - Les news Web Dev d’octobre 2025. Adonis, Laravel, React Compiler, Vite+ et bien plus encore ! @ Double Slash :fr:](https://double-slash.dev/podcasts/news-oct25/).]]>
            </summary>
            <updated>2025-10-16T06:36:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6292</id>
            <title type="text"><![CDATA[OSV]]></title>
            <link rel="alternate" href="https://osv.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6292"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A distributed vulnerability database for Open Source.
An open, precise, and distributed approach to producing and consuming vulnerability information for open source. 

- [OSV @ GitHub](https://github.com/google/osv.dev).
- [OSV-Scanner @ GitHub](https://github.com/google/osv-scanner/).

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).
- [Episode \#499 consacré aux référentiels de vulnérabilités @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/referentiels-de-vulnerabilites/).
- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).]]>
            </summary>
            <updated>2026-02-18T13:12:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6598</id>
            <title type="text"><![CDATA[Data Food Consortium]]></title>
            <link rel="alternate" href="https://www.datafoodconsortium.org/en/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6598"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A common and open digital language to develop short supply chains]]>
            </summary>
            <updated>2025-08-29T10:17:39+00:00</updated>
        </entry>
    </feed>
