Security●●Solid
Ghapin – Tool to pin GitHub Actions to SHAs for supply-chain security
Automates SHA pinning with --comment flag to preserve original tags inline.
Niche GemShip It
theden
203mo ago
SBOMs for CI/CD pipelines catch transitive action deps that grep misses entirely.
DevSecOps teams and security engineers using GitHub Actions
Snyk · Dependabot · Socket
Automates SHA pinning with --comment flag to preserve original tags inline.
Tarball diffing plus Claude analysis catches build.rs backdoors cargo-audit misses.
Single stdlib-only Python file means the supply chain tool has no supply chain.
Dependabot alternative with AI test generation and supply chain poisoning checks.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Dependabot already does this without the AI agent overhead.