Ghapin – Tool to pin GitHub Actions to SHAs for supply-chain security
Automates SHA pinning with --comment flag to preserve original tags inline.
SBOMs for CI/CD pipelines catch transitive action deps that grep misses entirely.
DevSecOps teams and security engineers using GitHub Actions
Snyk · Dependabot · Socket
Automates SHA pinning with --comment flag to preserve original tags inline.
Tarball diffing plus Claude analysis catches build.rs backdoors cargo-audit misses.
Dependabot alternative with AI test generation and supply chain poisoning checks.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Dependabot already does this without the AI agent overhead.
ReARM zeroes in on a gritty, enterprise problem: per-release evidence, automated changelogs, and 10+ year retention with product-level bundling and approval workflows. Integrations with Dependency-Track and OWASP TEx are smart moves, but the offering reads like a sensible commercial UX layer on top of existing provenance tools rather than a technical breakthrough.