Skip to content
#

supply-chain-security

Here are 21 public repositories matching this topic...

Experimental repository-local bootstrap for the Flix compiler: ./flixw <verb> downloads, digest-verifies, caches and runs the exact stock flix.jar pinned by the project. One dependency-free Java file, no Flix install, no compiler fork. Verified plugins and project tasks included.

  • Updated Sep 29, 2026
  • Java

Production-grade, secure-by-default Java/Spring Boot microservice templates for the US energy sector — aligned to EO 14028, NIST SP 800-53 Rev 5 and CISA Secure by Design. OIDC (Keycloak), Vault secrets, OpenTelemetry, CycloneDX SBOM, STRIDE threat models and CVE-gated CI.

  • Updated Jun 3, 2026
  • Java

fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。

  • Updated Sep 10, 2026
  • Java

Add this topic to your repo

To associate your repository with the supply-chain-security topic, visit your repo's landing page and select "manage topics."

Learn more