pack
📦
Supply Chain Security
supply-chain-security
SBOM generation, vulnerability scanning, image signing, and container hardening.
7 tools ★ 84.3k combined stars Security
install
Apply this pack
$ klim tool install --pack supply-chain-security
$ klim tool install --pack supply-chain-security
resolving 7 tools…
run klim plan show to preview before apply contents
7 tools
- →
Syft
syftCLI tool and library for generating a Software Bill of Materials from container images and filesystems
Security 2 package managers ★ 9.4k Apache-2.0 - →
OSV-Scanner
osv-scannerVulnerability scanner written in Go which uses the data provided by https://osv.dev
Security 2 package managers ★ 10.9k Apache-2.0 - →
Cosign
cosignCode signing and transparency for containers and binaries
Security 3 package managers ★ 6.2k Apache-2.0 - →
Trivy
trivyFind vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Security 5 package managers ★ 37.6k Apache-2.0 - →
grype
grypeA vulnerability scanner for container images and filesystems
Security 3 package managers ★ 12.8k Apache-2.0 - →
Dockle
dockleContainer Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
Security 2 package managers ★ 3.3k Apache-2.0 - →
crane
craneGo library and CLIs for working with container registries
Security 1 package managers ★ 4k Apache-2.0