Libraries tagged by supply chain
laravel/vet
6290 Downloads
A dependency audit trust file for PHP.
dgtlss/warden
81319 Downloads
A deterministic Laravel security gate for CI and deployment pipelines
cotonet/soak-time
20356 Downloads
Protects against supply chain attacks by filtering recently published packages.
k2gl/tuf
2789 Downloads
TUF (The Update Framework) client for PHP: fetch and verify signed metadata and targets
k2gl/slsa-provenance
1310 Downloads
SLSA Provenance predicates (v1 and v0.2) for PHP
k2gl/sigstore-verify
1976 Downloads
Offline Sigstore bundle verifier for PHP (Fulcio, Rekor, identity policy)
k2gl/signed-note
391 Downloads
Parse, verify and sign signed notes — the transparency-log / Go sumdb format used by Sigstore Rekor checkpoints — in PHP
k2gl/in-toto-attestation
3123 Downloads
Build, sign and verify in-toto attestation Statements (v1 and v0.1) in PHP
k2gl/dsse
4084 Downloads
Sign and verify DSSE (Dead Simple Signing Envelope) payloads in PHP, with pluggable keys
k2gl/composer-attest
1034 Downloads
Composer plugin that verifies GitHub build-provenance attestations for the packages you install
hexblot/composer-remediate
174 Downloads
Composer plugin that traces vulnerable dependencies to the packages you control and uses Composer's own solver to find the smallest verified upgrade that removes them.
nunomaduro/porto
10 Downloads
A dependency audit trust file for PHP.
nunomaduro/pet
9 Downloads
A dependency audit trust file for PHP.
innobrain/soak-time
3736 Downloads
Protects against supply chain attacks by filtering recently published packages.
encoredigitalgroup/heimdall
1067 Downloads
Heimdall — a Composer plugin that guards the bridge between Packagist and your vendor directory against supply chain attacks.