Skip to content
Change the repository type filter

All

    Repositories list

    • Long term storage of software bills of materials (sbom) https://arxiv.org/pdf/2303.11102.pdf
      Python
      1612Updated Feb 8, 2025Feb 8, 2025
    • longitudinal study of package registry growth
      Python
      0100Updated Feb 8, 2025Feb 8, 2025
    • flink

      Public
      Perpetual automerge for Apache Flink
      Java
      Apache License 2.0
      14k0125Updated Feb 8, 2025Feb 8, 2025
    • besu

      Public
      Perpetual automerge for Besu
      Java
      Apache License 2.0
      8810198Updated Feb 7, 2025Feb 7, 2025
    • Lockfiles for Maven. Pin your dependencies. Build with integrity.
      Java
      MIT License
      837128Updated Feb 7, 2025Feb 7, 2025
    • DDC4j

      Public
      diverse double compiling for Java. Bachelor thesis Elias.
      Shell
      MIT License
      0000Updated Feb 7, 2025Feb 7, 2025
    • ghasum

      Public
      Checksums for GitHub Actions.
      Go
      Apache License 2.0
      03100Updated Feb 7, 2025Feb 7, 2025
    • understanding the smart contract supply chain
      Jupyter Notebook
      MIT License
      02240Updated Feb 7, 2025Feb 7, 2025
    • ddc

      Public
      DDC for CI/CD master thesis Ludvig
      C
      0000Updated Feb 7, 2025Feb 7, 2025
    • Break the build if your supply chain is dirty
      MIT License
      0021Updated Feb 6, 2025Feb 6, 2025
    • The source for the website of the SSF CHAINS project https://chains.proj.kth.se/
      MIT License
      4800Updated Feb 6, 2025Feb 6, 2025
    • automatically detect software supply chain smells and issues
      Python
      MIT License
      112111Updated Feb 4, 2025Feb 4, 2025
    • bump

      Public
      A dataset of reproducible breaking dependency updates, SANER 2024 (https://doi.org/10.1109/SANER60148.2024.00024)
      Java
      MIT License
      61743Updated Jan 31, 2025Jan 31, 2025
    • swag

      Public
      software supply chain art
      Java
      00111Updated Jan 31, 2025Jan 31, 2025
    • sbom.exe

      Public
      calls the police if a prohibited class is loaded by the JVM http://arxiv.org/pdf/2407.00246
      Java
      MIT License
      0770Updated Jan 30, 2025Jan 30, 2025
    • that's the sound of sbom.exe
      Java
      0000Updated Jan 30, 2025Jan 30, 2025
    • classport

      Public
      Passports for Java class files
      Java
      MIT License
      00151Updated Jan 30, 2025Jan 30, 2025
    • spoon

      Public
      Perpetual automerge with CI for Spoon
      Java
      Other
      3580110Updated Jan 26, 2025Jan 26, 2025
    • sbom-mc

      Public
      Java
      Apache License 2.0
      4000Updated Jan 24, 2025Jan 24, 2025
    • A few more cents per minority client
      0250Updated Jan 23, 2025Jan 23, 2025
    • breaking-good

      Public template
      make breaking updates look good 👗 https://arxiv.org/abs/2407.03880
      Java
      MIT License
      2500Updated Jan 19, 2025Jan 19, 2025
    • goleash

      Public
      Runtime enforcement of software supply chain capabilities in Go
      C
      0010Updated Jan 13, 2025Jan 13, 2025
    • Listing and Counting Maven (sub)modules.
      Java
      0100Updated Jan 7, 2025Jan 7, 2025
    • coredns

      Public
      CoreDNS is a DNS server that chains plugins
      Go
      Apache License 2.0
      2.2k000Updated Jan 2, 2025Jan 2, 2025
    • bumper

      Public
      Fixing Breaking Dependency Updates With Large Language Models
      Jupyter Notebook
      MIT License
      0200Updated Nov 26, 2024Nov 26, 2024
    • A verifiable rebuilder for geth
      Go
      0250Updated Nov 12, 2024Nov 12, 2024
    • finding differences by the constant pool
      Java
      0031Updated Oct 27, 2024Oct 27, 2024
    • 0000Updated Oct 8, 2024Oct 8, 2024
    • GoSurf

      Public
      Static analyzer to find locations to hide malicious code in Go
      HTML
      1441Updated Oct 3, 2024Oct 3, 2024
    • theo

      Public
      Mapping runtime access privileges to third-party dependencies
      Java
      MIT License
      0000Updated Sep 14, 2024Sep 14, 2024