Skip to content

Add supply-chain-guard to Vulnerabilities and Security Advisories 馃馃馃 - #149

Open
homeofe wants to merge 1 commit into
lirantal:mainfrom
homeofe:add-supply-chain-guard
Open

Add supply-chain-guard to Vulnerabilities and Security Advisories 馃馃馃#149
homeofe wants to merge 1 commit into
lirantal:mainfrom
homeofe:add-supply-chain-guard

Conversation

@homeofe

@homeofe homeofe commented Jul 17, 2026

Copy link
Copy Markdown

Adds supply-chain-guard, an Apache-2.0 CLI + MCP server that scans npm dependencies for malware campaigns (GlassWorm, Shai-Hulud), typosquats and malicious install hooks before installation, with SLSA provenance grading and CycloneDX SBOM output. Fully offline/local.

Added to the end of the Vulnerabilities and Security Advisories section, one entry, capitalized and ending with a period per CONTRIBUTING.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant