Apps with 'Supply Chain Security' feature

All apps in Apps with 'Supply Chain Security' feature category. Use the filters below to narrow down your search. 
Copy a direct link to this comment to your clipboard
  1. OSS Rebuild icon
     3 likes

    Securing open-source package ecosystems by originating, validating, and augmenting build attestations.

    Cost / License

    Platforms

    • Go (Programming Language)
    • Linux
    • Mac
    • Windows
    • BSD
    • US flagUnited States
    OSS Rebuild screenshot 1
    16 alternatives
  2. Azure DevOps icon
     12 likes

    Continuous Delivery Services for teams to share code, track work, and ship software – for any language, all in a single package.

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Online
    • Microsoft Azure
    • US flagUnited States
    Azure DevOps screenshot 1
    Azure DevOps screenshot 1
    Azure DevOps screenshot 2
    +1
    Azure DevOps screenshot 3
    74 alternatives
  3. Vulert icon
     3 likes

    Vulert notifies you if a SECURITY ISSUE is found in any of the open-source software you use. No installation needed.

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Software as a Service (SaaS)
    Vulert intro
    only 2 steps to get started
    why vulert
    +2
    Vulert dashboard
    20 alternatives
  4. FOSSA icon
     3 likes

    FOSSA offers automated license scanning, dependency analysis and reports at each commit. Get a process up an running in 60 seconds, without slowing down development.

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Online
    25 alternatives
  5. PackageFix is a free browser-based dependency security fixer. Paste your manifest file and get back a fixed version with every vulnerable package patched — ready to download in one click.

    Cost / License

    • Free
    • Open Source (MIT)

    Application type

    Alerts

    • Discontinued

    Platforms

    • Online
    • US flagUnited States
    Live CVE scan via OSV database. CISA KEV banner flags actively exploited packages first. Health score, severity badges, fix versions, and side-by-side diff all in one view.
    Supports 7 ecosystems — paste or drop your manifest file, or load a built-in example. Auto-detects npm, PyPI, Ruby, PHP, Go, Rust, and Java/Maven.
    Runs entirely in your browser - no signup, no CLI, no GitHub connection. Queries OSV, CISA KEV, and package registries live. Results in under 5 seconds.
    17 alternatives
  6. NeuVector icon
     Like

    NeuVector Full Lifecycle Container Security Platform delivers the only cloud-native security with end-to-end protection from DevOps vulnerability protection to automated run-time security, and featuring a true Layer 7 container firewall.

    Cost / License

    Platforms

    • Linux
    • Self-Hosted
    • US flagUnited States
    NeuVector screenshot 1
    9 alternatives
  7. Vibgrate icon
     Like

    Local CLI that scores dependency and runtime drift, checks known vulnerabilities, maps code relationships, and ranks upgrade work for CI.

    Cost / License

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • Software as a Service (SaaS)
    • Docker
    • GB flagUnited Kingdom
    Vibgrate screenshot 1
    One command scans any repo for upgrade drift — a 0–100 DriftScore, the vulnerabilities hiding in stale dependencies, and the upgrade path to clear them.
    DriftScore in VS Code - The number, what’s in it, the EOL horizon, and a 90-day trend — one click from the activity bar.
    +2
    A vg review scan showing a breach of the declared architecture boundary by a Controller reaching the persistence layer.
    14 alternatives
  8. sbomify icon
     Like

    sbomify is the trust center for your software supply chain. Store every SBOM and compliance document in one place, track them across products and releases, and share them with customers and regulators on demand. CycloneDX and SPDX, built for EU CRA compliance.

    Cost / License

    Platforms

    • Online
    • Linux
    • Docker
    • GB flagUnited Kingdom
    sbomify screenshot 1
    sbomify screenshot 1
    sbomify screenshot 2
    +13
    sbomify screenshot 3
    5 alternatives
  9. Sepio icon
     Like

    Founded in 2016 by cybersecurity industry veterans, Sepio’s HAC-1 is the first hardware access control platform that provides visibility, control, and mitigation to zero trust, insider threat, BYOD, IT, OT and IoT security programs.

    Cost / License

    • Free
    • Proprietary

    Platforms

    • Online
    • Software as a Service (SaaS)
    Sepio screenshot 1
    Sepio screenshot 1
    Sepio screenshot 2
  10. HOL Guard icon
     Like

    HOL Guard is an open-source, local-first runtime security layer for AI agents and automation. It sits between any AI harness and the tools it wants to run, pausing risky package installs, secret reads, shell commands, and MCP changes for review before execution.

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • Docker
    • MH flagMarshall Islands
    HOL Guard screenshot 1
    HOL Guard screenshot 1
    HOL Guard screenshot 2
    +6
    HOL Guard screenshot 3
    8 alternatives
  11. Generates SBOMs during CI from lockfiles, containers, and directories using native tooling with ecosystem coverage, metadata enrichment, trusted outputs, and OIDC publishing.

    Cost / License

    Platforms

    • Linux
    • Docker
    • GB flagUnited Kingdom
    sbomify action screenshot 1
    1 alternatives
  12. vet icon
     Like

    vet is a tool for protecting against open source software supply chain attacks. To adapt to organizational needs, it uses an opinionated policy expressed as Common Expressions Language and extensive package security metadata including:

    Cost / License

    Platforms

    • Mac
    • Linux
    • Homebrew
    • IN flagIndia
    vet screenshot 1
    vet screenshot 1
    vet screenshot 2
    28 alternatives