Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
chain-bench — Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD pipelines for risks. | Kitploit
Tools/GitHubGitHub/aquasecurity/chain-bench
Vulnerability ScannersConfiguration AuditingDevSecOpsSupply Chain Security
GitHubaquasecurity/chain-bench

chain-bench

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD pipelines for risks.

View Repository
77463632 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

chain-bench logo

[📖 Documentation][docs]

Chain-bench is an open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark. The auditing focuses on the entire SDLC process, where it can reveal risks from code time into deploy time. To win the race against hackers and protect your sensitive data and customer trust, you need to ensure your code is compliant with your organization’s policies.

Read more in the [Chain-bench Documentation][docs]

Go Reference GitHub Release Downloads DockerHub Pulls Build Status License go-report-card

demo

Contents

  • Contents
  • Introduction
  • Quick start
    • Installation
    • Usage
      • Using docker
      • Using GitHub Actions
      • Using Gitlab CI (beta)
  • Requirements
  • Supported Providers
  • Please Note
  • Contributing
  • Roadmap

Introduction

Chain-bench is an open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark. The auditing focuses on the entire SDLC process, where it can reveal risks from code time into deploy time.

Quick start

The primary way to run chain-bench is as a standalone cli. It requires an access token for your account and the repository url in order to access your SCM.

Installation

Get Chain-bench via your favorite installation method. See [installation] section in the documentation for details. For example:

  • brew install chain-bench
  • nix-env --install -A nixpkgs.chain-bench
  • docker run aquasec/chain-bench
  • Download binary from https://github.com/aquasecurity/chain-bench/releases/latest/

Usage

chain-bench scan --repository-url <REPOSITORY_URL> --access-token <TOKEN> -o <OUTPUT_PATH>

Using Self-hosted or Dedicated SCM Platforms (with custom domains)

chain-bench scan --repository-url <REPOSITORY_URL> --scm-platform <SCM_PLATFORM> --access-token <TOKEN> -o <OUTPUT_PATH>

Supported options for scm-platform are "github" and "gitlab" (beta)

Using docker

docker run aquasec/chain-bench scan --repository-url <REPOSITORY_URL> --access-token <TOKEN>

Using GitHub Actions

See the repository at https://github.com/aquasecurity/chain-bench-action

Example output
Download Tool