Open source supply-chain projects
Every project in the registry tagged supply-chain, ranked by real GitHub adoption.
Go implementation of The Update Framework (TUF)
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
Common go library shared across sigstore services and clients
Related tags
Frequently asked questions
How many open source supply-chain projects are there?
This registry tracks 4 projects tagged supply-chain, with 2,422 GitHub stars between them. The most-adopted is go-tuf at 717 stars.
Are these supply-chain projects free to use?
Yes — 4 of the 4 carry an explicit open-source licence across 2 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which supply-chain project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these supply-chain projects still maintained?
3 of the 4 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.