
Wisec
Stop blindly trusting your software supply chain.
What it does
Software supply chain attacks are rising. Most teams scan for CVEs but ignore build integrity and provenance. Wisec fixes this: → ED25519 cryptographic signatures on every build → Immutable provenance on IPFS → Behavioral anomaly detection (new deps, unknown contributors, hardcoded secrets...) → Real-time risk scoring dashboard 🛠️ 1 agent. 1 line in your pipeline. No source code stored. 🇫🇷 Built by a solo DevOps engineer. 🎁 Free plan available - no credit card required.
Does the same job
all alternatives →
- TTTips to stay safe from NPM supply chain attacksSep 2025 · github.com · ▲96
Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community. Cheers!

- CAChainloop, A Software Supply Chain Attestation solution devs won't hate2023 · github.com · ▲45
Hi, my name is Miguel and I am very happy to share what's been months worth of work :) The project has rough edges for sure, but any early feedback, comments or concerns are appreciated! === The Problem === You work on the Security and Operations (SecOps) team in charge of your organization's Software Supply Chain Security. You feel pretty good about the state of things already, your developer teams are signing their commits, deliverables, scanning for vulnerabilities,… Life is good! Then you realize that you are not compliant with the latest security requirements. You get referred to…
- TDTrusty – Dependency Software Supply Chain Security2023 · trustypkg.dev · ▲14
Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…
- SZSecureBuild – Zero-CVE Images That Pay OSS Projects2025 · securebuild.com · ▲40
We're launching SecureBuild: https://securebuild.com — a new way for open source projects and maintainers to earn revenue by partnering with and endorsing our Zero-CVE container images of their project. We’ve spent the last decade at Replicated (https://news.ycombinator.com/item?id=9841243) helping commercial and open source software vendors securely distribute their apps to enterprise environments. During that time, we saw firsthand how hard it is for maintainers to fund their work, and how increasingly demanding enterprises have become when it comes to demonstrable…
More dev tools this month
the category →



The first open-source price index for GPU compute
Dev tools · 10d ago · getcomputable.com

OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.
Dev tools · 2d ago · opentrailpaper.com

Open-source GTM skills for technical founders
Dev tools · 29d ago · gtmcofounder.com
Launched alongside, March 2026
the whole month →

Switch from ChatGPT to Claude with import memory feature
AI · Mar 2026 · claude.com


