Currently building:
██████╗ ██████╗ ███████╗███████╗ █████╗ ███╗ ███╗███████╗██████╗
██╔════╝ ██╔═══██╗██╔════╝██╔════╝██╔══██╗████╗ ████║██╔════╝██╔══██╗
██║ ███╗██║ ██║███████╗███████╗███████║██╔████╔██║█████╗ ██████╔╝
██║ ██║██║ ██║╚════██║╚════██║██╔══██║██║╚██╔╝██║██╔══╝ ██╔══██╗
╚██████╔╝╚██████╔╝███████║███████║██║ ██║██║ ╚═╝ ██║███████╗██║ ██║
╚═════╝ ╚═════╝ ╚══════╝╚══════╝╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝
A lightweight software supply chain security suite.
| Project | Description | Status |
|---|---|---|
| tokenwatch | Detects secrets and credential exposure across a repository's entire Git history. | ✅ |
| pipewatch | Audits CI/CD pipelines for tampering, insecure workflows, and integrity drift. | ✅ |
| VSac, formerly XBOM | Threat intelligence, dependency analysis, SBOM generation, and vulnerability correlation. | ✅ |
| Molt | Configuration drift detection, artifact verification, and container security. | 🚧 |
| Web | Unified dashboard aggregating findings across the GOSSAMER ecosystem. | 🚧 |