PyPI Stats
  • Insights
  • PyPI
  • GitHub
  • Search
  • Compare
  • Advisories
  • Ecosystem
  • About
Home

Supply Chain Python Packages

Python packages with the GitHub topic supply-chain. Sorted by relevance, with stars and monthly downloads.
pypa
pip-audit

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

13.6M 1K 93
sigstore
sigstore

A Sigstore client written in Python

320K 317 75
in-toto
in-toto

in-toto is a framework to protect supply chain integrity.

66K 1K 154
ochronasec
ochrona

A command line tool for detecting vulnerabilities in Python dependencies and doing safe package installs

18K 51 8
johhnyg
stillrunning

Enterprise security and monitoring for developers. pip install stillrunning

10K 0 0
twu
skjold

Security audit Python project dependencies against security advisory databases.

8K 67 13
sigstore
model-signing

Supply chain security for ML

8K 230 59
LarrySnyder
stockpyl

Python inventory optimization and simulation tools.

4K 161 29
ai-vnv
deepbullwhip

Multi-tier supply chain bullwhip effect simulator

3K 0 0
CSOAI-ORG
ai-bom-mcp

AI Bill of Materials (AI-BOM) generator + auditor MCP — CycloneDX ML-BOM, SPDX 3.0 AI profile, EU AI Act Annex IV mapping, NIST AI RMF alignment, US EO 14028 federal procurement. By MEOK AI Labs.

2K 0 0
tilakthimmappa
pyraider

Using PyRaider You can scan installed dependencies known security vulnerabilities. It uses publicly known exploits, vulnerabilities database.

1K 18 0
greyllmmoder
aztec-py

Pure-Python Aztec Code barcode generator — GS1 2027 compliant, IATA BCBP, batch encoding, SVG/PDF/PNG, CLI. Zero deps. ISO 24778.

1K 1 0
chris48s
pip-abandoned

📦 Search for abandoned and deprecated python packages

1K 9 0
alekssadowski95
openpartslibrary

OpenPartsLibrary is a Python library designed to serve as a centralized parts database for Bill of Materials (BOM), Product Data Management (PDM), and Product Lifecycle Management (PLM) systems.

1K 9 2
reservoir-data
tap-socketdev

Singer tap for Socket, built with the Meltano SDK for Singer Taps.

1K 0 0
kulkansecurity
gitxray

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

1K 179 14
eclipse-csi
otterdog

OtterDog is a tool to manage GitHub organizations at scale using a configuration as code approach. It is actively used by the Eclipse Foundation to manage its numerous projects hosted on GitHub.

1K 47 19
checkmarx
chainjacking

Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks

871 63 15
microsoft
pyscitt

Supply Chain Integrity Transparency and Trust ledger application using Confidential Consortium Framework (CCF)

623 44 25
ossillate-inc
packj

Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain

570 685 37
SemClone
ospac

Open Source Policy as Code - License compliance policy engine

494 0 1
hubbs5
or-gym

Environments for OR and RL Research

460 441 98
johhnyg
pkl-inspector

Static analysis for Python pickle files — detects malicious code without executing it. Patent Pending.

421 0 0
copyleftdev
x12-python

The ultimate Python toolkit for X12 EDI processing. Parse, validate, and generate healthcare (837, 835, 270/271) and supply chain (850, 856, 810) transactions with HIPAA compliance.

408 4 0
    • Data from PyPI, GitHub, ClickHouse, and BigQuery