Alternatives
Products that do what SBOM Archi does
Continuous SBOM Risk Management for Software Supply Chains
- 1

- 2SS
Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…
2022 · socket.dev
- 3

- 4

- 5

- 6

- 7

- 8

- 9

- 10

- 11

- 12

- 13CA
Hi, my name is Miguel and I am very happy to share what's been months worth of work :) The project has rough edges for sure, but any early feedback, comments or concerns are appreciated! === The Problem === You work on the Security and Operations (SecOps) team in charge of your organization's Software Supply Chain Security. You feel pretty good about the state of things already, your developer teams are signing their commits, deliverables, scanning for vulnerabilities,… Life is good! Then you realize that you are not compliant with the latest security requirements. You get referred to…
2023 · github.com
- 14TT
Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community. Cheers!
Sep 2025 · github.com
- 15

- 16

Build smart search experiences in hours instead of months
2020
- 17

- 18NI
Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware
2022 · github.com
- 19OS
Hey HN, I am the founder of Tensorlake. Prototyping LLM applications have become a lot easier, building decision making LLM applications that work on constantly updating data is still very challenging in production settings. The systems engineering problems that we have seen people face are - 1. Reliably process ingested content in real time if the application is sensitive to freshness of information. 2. Being able to bring in any kind of model, and run different parts of the pipeline on GPUs and CPUs. 3. Fault Tolerance to ingestion spike, compute infrastructure failure. 4. Scaling compute,…
2024 · getindexify.ai
- 20

- 21AL
Hey HN, I'm a bootstrap SaaS founder that trying to grow my micro SaaS. I've been doing pivot many times and this may be the last straw. I realized that marketing and sales are key in building business but cold outbound is suck! So I built a tool to help SaaS founders identify unhappy customers from their competitors to pitch their SaaS. This feature is specifically requested by Peer - Cal.com CEO from my interaction with him here - https://x.com/heykaiyo/status/1821216800610382013 I hope this small tool would be helpful. Would love your feedback pls. Anyone…
2024 · loom.com
- 22SZ
We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…
2025 · securebuild.com
- 23AA
Hello HN Community, As an ex-founder of a developers-for-hire agency, I was fortunate to build for many different software organizations around the world, and partner with the most talented product teams. One of the things I learned by coding was how painful it is to build & maintain pricing in SaaS. The pricing structure and logic always end up being coupled with the core application code and the billing platform. The product catalog is typically managed in spreadsheets, by the product & monetization teams, while all the possible package types, including the legacy ones, are typically…
2022 · docs.stigg.io
- 24TD
Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…
2023 · trustypkg.dev
Ranked by how close each launch is in meaning, then by votes. Refine with a description →