Skip to content
Change the repository type filter

All

    Repositories list

    • besu

      Public
      Perpetual automerge for Besu
      Java
      1k0197Updated Feb 20, 2026Feb 20, 2026
    • Long term storage of software bills of materials (sbom) https://arxiv.org/pdf/2303.11102.pdf
      Python
      2712Updated Feb 20, 2026Feb 20, 2026
    • flink

      Public
      Perpetual automerge for Apache Flink
      Java
      14k0123Updated Feb 20, 2026Feb 20, 2026
    • aotp

      Public
      Looking inside AOTCache
      Java
      0040Updated Feb 20, 2026Feb 20, 2026
    • longitudinal study of package registry growth
      Python
      0100Updated Feb 20, 2026Feb 20, 2026
    • bump

      Public
      A dataset of reproducible breaking dependency updates, SANER 2024 (https://doi.org/10.1109/SANER60148.2024.00024)
      Java
      82155Updated Feb 20, 2026Feb 20, 2026
    • ghasum

      Public
      Checksums for GitHub Actions.
      Go
      118201Updated Feb 19, 2026Feb 19, 2026
    • The source for the website of the SSF CHAINS project https://chains.proj.kth.se/
      HTML
      11800Updated Feb 18, 2026Feb 18, 2026
    • zkSBOM

      Public
      zero knowledge SBOMs (thesis Tom Sorger)
      Rust
      0300Updated Feb 17, 2026Feb 17, 2026
    • oZKS

      Public
      oZKS (Ordered Zero-Knowledge Set) is a library that provides an implementation of an Ordered (and Append Only) Zero-Knowledge Set.
      C++
      7000Updated Feb 17, 2026Feb 17, 2026
    • Lockfiles for Maven. Pin your dependencies. Build with integrity.
      Java
      1455156Updated Feb 16, 2026Feb 16, 2026
    • sbom.exe

      Public
      calls the police if a prohibited class is loaded by the JVM http://arxiv.org/pdf/2407.00246
      Java
      1997Updated Feb 15, 2026Feb 15, 2026
    • automatically detect software supply chain smells and issues http://arxiv.org/pdf/2410.16049
      Python
      518305Updated Feb 13, 2026Feb 13, 2026
    • Break the build if your supply chain is dirty
      0265Updated Feb 12, 2026Feb 12, 2026
    • pypi1000

      Public
      1000 Github repositories on Pypi
      Python
      0000Updated Feb 9, 2026Feb 9, 2026
    • reproducible build study of javascript bundling (thesis E. Vitell)
      Python
      0000Updated Feb 9, 2026Feb 9, 2026
    • bombom

      Public
      grassroot bill of materials for linux
      Python
      0000Updated Feb 8, 2026Feb 8, 2026
    • Scripts used to retrieve data and acquire results for dirty-waters
      Jupyter Notebook
      0000Updated Feb 6, 2026Feb 6, 2026
    • swag

      Public
      software supply chain art
      Java
      12111Updated Feb 1, 2026Feb 1, 2026
    • Java-Class-Hijack: Software Supply Chain Attack for Java based on Maven Dependency Resolution and Java Classloading
      Java
      1300Updated Jan 30, 2026Jan 30, 2026
    • spoon

      Public
      Perpetual automerge with CI for Spoon
      Java
      3750110Updated Jan 23, 2026Jan 23, 2026
    • Experiments related to the Classport projects
      Java
      0010Updated Jan 21, 2026Jan 21, 2026
    • classport

      Public
      Passports for Java class files
      Java
      12140Updated Jan 20, 2026Jan 20, 2026
    • Java
      0010Updated Nov 25, 2025Nov 25, 2025
    • Reproducible Central: rebuild instructions for artifacts published to (Maven) Central Repository
      Java
      610160Updated Nov 15, 2025Nov 15, 2025
    • goleash

      Public
      Runtime enforcement of software supply chain capabilities in Go
      C
      01910Updated Nov 12, 2025Nov 12, 2025
    • Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
      Go
      46000Updated Oct 24, 2025Oct 24, 2025
    • Java
      0200Updated Oct 18, 2025Oct 18, 2025
    • diffonomy

      Public
      diffoscope report analysis tool
      Python
      0100Updated Sep 22, 2025Sep 22, 2025
    • Securing the Bitcoin software supply chain with an immutable database of SHA256
      Python
      1112Updated Sep 5, 2025Sep 5, 2025