Skip to content

Supply Chain Security

SBOM generation, software signing, policy-as-code, and dependency vulnerability scanning.

Subscribe
← Releases
Review required
msaad00/agent-bom v0.88.5 New feature
Auth RBAC Breaking upgrade

UI, onboarding, gateway, findings, observability, graph, hardening, deps, runtime

Review required
qwexvf/aegis-cli v0.28.0 New feature
Dependencies

@qwexvf CLI, registry, AST, heuristics, docs

v2.3.0 (9d) Blast Radius CLI + exposure
Review required
ErenAri/Aegis-BPF v0.8.0 New feature
Auth RBAC Dependencies

Ed25519 signing, CEF format, rule library, BTFhub download

No immediate action
pentest-ai v0.15.3 New feature

Budget default increase

v0.15.2 (14d) Auth inheritance in MCP calls
v0.15.0 (14d) Safety flags + bearer auth
v0.26.0 (17d) AST scan + lockfile extraction
v0.20.0 (20d) Licensefetch + heuristics
v0.19.0 (20d) New ecosystems + cloud analysis
Upgrade now
goklab/guardvibe v3.1.23 New feature
Dependencies Breaking upgrade

dep-CVE rules + dependency hygiene

No immediate action
pentest-ai v0.14.0 New feature

Plan/ensure tools, expanded agent loop, smart install

v0.15.1 (23d) Per‑PM release archives
v0.15.0 (23d) Maintainer‑transfer + drift detector
v0.12.0 (28d) Java + PHP scanners + lockfile parsers
v0.11.0 (28d) Go & Rust AST scanners
v0.10.0 (28d) Ruby AST scanner + local analysis
Review required
qwexvf/aegis-cli v0.9.0 New feature
Dependencies

Multi‑language scans + typosquat detection

Beta — feedback welcome: [email protected]