Skip to content
Change the repository type filter

All

    Repositories list

    • flink

      Public
      Perpetual automerge for Apache Flink
      Java
      Apache License 2.0
      13k0126Updated Oct 3, 2024Oct 3, 2024
    • GoSurf

      Public
      Static analyzer to find locations to hide malicious code in Go
      HTML
      1241Updated Oct 3, 2024Oct 3, 2024
    • longitudinal study of package registry growth
      0000Updated Oct 3, 2024Oct 3, 2024
    • Lockfiles for Maven. Pin your dependencies. Build with integrity.
      Java
      MIT License
      931103Updated Oct 2, 2024Oct 2, 2024
    • goleash

      Public
      Runtime enforcement of software supply chain capabilities in Go
      C
      0000Updated Oct 2, 2024Oct 2, 2024
    • coredns

      Public
      CoreDNS is a DNS server that chains plugins
      Go
      Apache License 2.0
      2.1k000Updated Oct 2, 2024Oct 2, 2024
    • sbom.exe

      Public
      calls the police if a prohibited class is loaded by the JVM http://arxiv.org/pdf/2407.00246
      Java
      MIT License
      0680Updated Oct 2, 2024Oct 2, 2024
    • besu

      Public
      Perpetual automerge for Besu
      Java
      Apache License 2.0
      8120193Updated Oct 1, 2024Oct 1, 2024
    • Long term storage of software bills of materials (sbom) https://arxiv.org/pdf/2303.11102.pdf
      Python
      1612Updated Oct 1, 2024Oct 1, 2024
    • scsc

      Public
      smart contract supply chain
      Python
      02160Updated Sep 29, 2024Sep 29, 2024
    • The source for the website of the SSF CHAINS project https://chains.proj.kth.se/
      MIT License
      3700Updated Sep 27, 2024Sep 27, 2024
    • bump

      Public
      A dataset of reproducible breaking dependency updates, SANER 2024 (https://doi.org/10.1109/SANER60148.2024.00024)
      Java
      MIT License
      51541Updated Sep 27, 2024Sep 27, 2024
    • spoon

      Public
      Perpetual automerge with CI for Spoon
      Java
      Other
      3470110Updated Sep 25, 2024Sep 25, 2024
    • A few more cents per minority client
      0240Updated Sep 19, 2024Sep 19, 2024
    • theo

      Public
      Mapping runtime access privileges to third-party dependencies
      Java
      MIT License
      0000Updated Sep 14, 2024Sep 14, 2024
    • finding differences by the constant pool
      Java
      0021Updated Sep 10, 2024Sep 10, 2024
    • that's the sound of sbom.exe
      Java
      0000Updated Sep 5, 2024Sep 5, 2024
    • swag

      Public
      software supply chain art
      Java
      00111Updated Aug 27, 2024Aug 27, 2024
    • breaking-good

      Public template
      make breaking updates look good 👗 https://arxiv.org/abs/2407.03880
      Java
      MIT License
      2520Updated Aug 26, 2024Aug 26, 2024
    • A verifiable rebuilder for geth
      Go
      0140Updated Aug 22, 2024Aug 22, 2024
    • Securing the Bitcoin software supply chain with an immutable database of SHA256
      Python
      1112Updated Aug 8, 2024Aug 8, 2024
    • classport

      Public
      Passports for Java class files
      Java
      MIT License
      0070Updated Jun 17, 2024Jun 17, 2024
    • Java
      MIT License
      0000Updated Jun 13, 2024Jun 13, 2024
    • Side data repo for breaking updates
      Java
      2000Updated May 14, 2024May 14, 2024
    • log4shell-poc

      Public archive
      executable log4shell attack
      Java
      0000Updated Apr 29, 2024Apr 29, 2024
    • Java
      2000Updated Apr 20, 2024Apr 20, 2024
    • A sample Spring-based application
      CSS
      Apache License 2.0
      24k000Updated Apr 3, 2024Apr 3, 2024
    • playing sboms on stage
      0100Updated Mar 27, 2024Mar 27, 2024
    • A malicious LDAP server for JNDI injection attacks
      Java
      MIT License
      220000Updated Mar 6, 2024Mar 6, 2024
    • 1000py

      Public
      automerge in python
      0000Updated Jan 18, 2024Jan 18, 2024