Skip to content

Supply Chain Security

SBOM generation, software signing, policy-as-code, and dependency vulnerability scanning.

Subscribe
← Releases
No immediate action
isitsecure v0.5.0 New feature

MCP scan server + CI fixes

No immediate action
isitsecure v0.3.0 New feature

Plain‑English framing

v0.2.1 (14d) Auth‑bypass SQLi detection
v0.1.0 (16d) Scanning + blind injection
No immediate action
VulnerableApp 2.1.0 New feature

Modules, Challenge Cards, Infrastructure, Docs, Contributors

Review required
msaad00/agent-bom v0.91.0 New feature
Auth RBAC

UI design system, SCA, output, MCP, version, gateway

v3.23.0 (1mo) VG1094 extension + VG973 narrowing
v3.22.0 (1mo) hallucinated-packages scanner
v3.12.0 (1mo) proofTest from secure_this
v3.11.0 (1mo) Prioritized audit findings
v3.10.0 (1mo) CVE prioritization + rule scaffolding
v3.9.0 (1mo) default diff-aware scan
v3.7.0 (1mo) Three new CVE rules
v3.5.0 (1mo) Agent output format
v3.4.0 (1mo) Reachability annotation
v3.3.0 (1mo) Diff‑aware default behavior
v3.2.0 (1mo) secure_this tool
v3.1.41 (1mo) FAQ addition
v3.1.40 (1mo) Flags direct request body in Mongoose updates
v3.1.39 (1mo) SSRF taint detection

Beta — feedback welcome: [email protected]