Skip to content
Change the repository type filter

All

    Repositories list

    • flink

      Public
      Perpetual automerge for Apache Flink
      Java
      14k0125Updated Sep 21, 2025Sep 21, 2025
    • besu

      Public
      Perpetual automerge for Besu
      Java
      9640197Updated Sep 21, 2025Sep 21, 2025
    • Long term storage of software bills of materials (sbom) https://arxiv.org/pdf/2303.11102.pdf
      Python
      1612Updated Sep 21, 2025Sep 21, 2025
    • Lockfiles for Maven. Pin your dependencies. Build with integrity.
      Java
      1246175Updated Sep 21, 2025Sep 21, 2025
    • sbom.exe

      Public
      calls the police if a prohibited class is loaded by the JVM http://arxiv.org/pdf/2407.00246
      Java
      1874Updated Sep 21, 2025Sep 21, 2025
    • ghasum

      Public
      Checksums for GitHub Actions.
      Go
      115120Updated Sep 20, 2025Sep 20, 2025
    • automatically detect software supply chain smells and issues http://arxiv.org/pdf/2410.16049
      Python
      417289Updated Sep 19, 2025Sep 19, 2025
    • Break the build if your supply chain is dirty
      0162Updated Sep 18, 2025Sep 18, 2025
    • bombom

      Public
      grassroot bill of materials for linux
      Python
      0000Updated Sep 17, 2025Sep 17, 2025
    • longitudinal study of package registry growth
      Python
      0100Updated Sep 17, 2025Sep 17, 2025
    • swag

      Public
      software supply chain art
      Java
      12111Updated Sep 13, 2025Sep 13, 2025
    • The source for the website of the SSF CHAINS project https://chains.proj.kth.se/
      HTML
      9800Updated Sep 10, 2025Sep 10, 2025
    • spoon

      Public
      Perpetual automerge with CI for Spoon
      Java
      3640110Updated Sep 8, 2025Sep 8, 2025
    • Reproducible Central: rebuild instructions for artifacts published to (Maven) Central Repository
      Java
      570160Updated Sep 8, 2025Sep 8, 2025
    • Securing the Bitcoin software supply chain with an immutable database of SHA256
      Python
      1112Updated Sep 5, 2025Sep 5, 2025
    • bacardi

      Public
      fix breaking dependency updates 🛠️
      Java
      2360Updated Sep 5, 2025Sep 5, 2025
    • bump

      Public
      A dataset of reproducible breaking dependency updates, SANER 2024 (https://doi.org/10.1109/SANER60148.2024.00024)
      Java
      820410Updated Sep 4, 2025Sep 4, 2025
    • theo

      Public
      Mapping runtime access privileges to third-party dependencies
      Java
      0000Updated Sep 1, 2025Sep 1, 2025
    • DDC4j

      Public
      Diverse double compiling for Java. Bachelor thesis Elias and Eskil.
      Shell
      0000Updated Aug 27, 2025Aug 27, 2025
    • diffonomy

      Public
      diffoscope report analysis tool
      Python
      0000Updated Aug 22, 2025Aug 22, 2025
    • Side data repo for breaking updates
      Java
      2000Updated Aug 21, 2025Aug 21, 2025
    • zkSBOM

      Public
      zero knowledge SBOMs (thesis Tom Sorger)
      Rust
      0200Updated Aug 20, 2025Aug 20, 2025
    • Securing open-source package ecosystems by originating, validating, and augmenting build attestations.
      Go
      34000Updated Aug 15, 2025Aug 15, 2025
    • Detect semantic changes in dependency updates using dynamic analysis
      Java
      0200Updated Aug 14, 2025Aug 14, 2025
    • goleash

      Public
      Runtime enforcement of software supply chain capabilities in Go
      C
      01810Updated Jul 30, 2025Jul 30, 2025
    • Listing and Counting Maven (sub)modules.
      Java
      0111Updated Jul 24, 2025Jul 24, 2025
    • classport

      Public
      Passports for Java class files
      Java
      12160Updated Jul 14, 2025Jul 14, 2025
    • Experiments related to the Classport projects
      Java
      0000Updated Jul 7, 2025Jul 7, 2025
    • that's the sound of sbom.exe
      Java
      0000Updated Jul 4, 2025Jul 4, 2025
    • ddc4cd

      Public
      DDC for CI/CD master thesis Ludvig
      Shell
      0130Updated Jul 2, 2025Jul 2, 2025