Open source supply-chain projects

Every project in the registry tagged supply-chain, ranked by real GitHub adoption.

projects 4 combined stars ★ 2.4K refresh nightly
01 go-tuf ★ 717

Go implementation of The Update Framework (TUF)

last push37 hours ago languageGo licenseApache-2.0
02 bomber ★ 624

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

last push7 months ago languageGo licenseMPL-2.0
03 witness ★ 546

Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.

last push32 hours ago languageGo licenseApache-2.0
04 sigstore ★ 535

Common go library shared across sigstore services and clients

last push3 days ago languageGo licenseApache-2.0

Related tags

← all tags

Frequently asked questions

How many open source supply-chain projects are there?

This registry tracks 4 projects tagged supply-chain, with 2,422 GitHub stars between them. The most-adopted is go-tuf at 717 stars.

Are these supply-chain projects free to use?

Yes — 4 of the 4 carry an explicit open-source licence across 2 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which supply-chain project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these supply-chain projects still maintained?

3 of the 4 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.