Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k17h 55m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k15h 10m ago
grype preview#3

grype

GitHubanchore/grype
12.7k5 days ago
syft preview#4

syft

GitHubanchore/syft
9.6k5 days ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k15 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k5 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k1 day ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
541 day ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
778 results
safe-chain preview

safe-chain

GitHubaikidosec/safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

defensive-toolsvulnerability-scannersmalware-analysis+3
1.7k1 day ago
cplt preview

cplt

GitHubnavikt/cplt

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

defensive-toolsdynamic-analysis-sandboxingconfiguration-auditing+7
1211 day ago
dependency-track preview

dependency-track

GitHubdependencytrack/dependency-track

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

vulnerability-analysisdevsecopssupply-chain-security
4.1k1 day ago
vex8s preview

vex8s

GitHubalegrey91/vex8s

Suppress vulnerabilities applying Kubernetes context to scans

cloud-infrastructure-securityvulnerability-scannerscontainer-security+7
201 day ago
DependencyCheck preview

DependencyCheck

GitHubdependency-check/dependencycheck

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

vulnerability-scannersvulnerability-analysisdevsecops+1
7.7k1 day ago
Harden-Windows-Security preview

Harden-Windows-Security

GitHubhotcakex/harden-windows-security

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

defensive-toolsencryption-decryption-toolsconfiguration-auditing+3
4.5k1 day ago
cryptoptic preview

cryptoptic

GitHubnationwide-group-oss/cryptoptic

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

defensive-toolsstatic-code-analysisvulnerability-analysis+6
1 day ago
ndaal_public_SBOM_Auditor preview

ndaal_public_SBOM_Auditor

GitLabvpierre/ndaal_public_sbom_auditor

Offline single-binary web app that ingests CycloneDX, SPDX and syft SBOMs, runs an ensemble of CVE scanners, enriches findings with EPSS, CISA-KEV…

defensive-toolsioc-managementstatic-analysis+7
1 day ago
python-tuf preview

python-tuf

GitHubtheupdateframework/python-tuf

Python reference implementation of The Update Framework (TUF)

cryptographyutilities-frameworkssupply-chain-security
1.7k1 day ago
securesystemslib preview

securesystemslib

GitHubsecure-systems-lab/securesystemslib

Cryptographic and general-purpose routines for Secure Systems Lab projects at NYU

cryptographyhardware-securitysupply-chain-security+1
541 day ago
capslock preview

capslock

GitHubgoogle/capslock

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

static-analysisvulnerability-analysiscode-analysis+2
1.2k1 day ago
skill-scanner preview

skill-scanner

GitHubcisco-ai-defense/skill-scanner

Security Scanner for Agent Skills

static-analysisvulnerability-scannersdynamic-analysis-sandboxing+9
2.4k1 day ago
ws4-secure-design-agentic-systems preview

ws4-secure-design-agentic-systems

GitHubcosai-oasis/ws4-secure-design-agentic-systems

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

cloud-securitythreat-intelligenceidentity-access-management+6
1261 day ago
guac preview

guac

GitHubguacsec/guac

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

vulnerability-analysissupply-chain-security
1.5k1 day ago
skills preview

skills

GitHubtrailofbits/skills

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

static-analysisvulnerability-analysiscode-analysis+8
6.5k2 days ago
zizmor preview

zizmor

GitHubzizmorcore/zizmor

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

static-analysisvulnerability-analysiscode-analysis+5
6.0k2 days ago
dep-scan preview

dep-scan

GitHubowasp-dep-scan/dep-scan

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

vulnerability-scannerscontainer-securitydevsecops+1
1.3k2 days ago
OpenAnt preview

OpenAnt

GitHubknostic/openant

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

vulnerability-scannersdynamic-analysis-sandboxingstatic-code-analysis+4
7182 days ago
Previous1234…44Next