Skip to content

Add Proof of Commitment to Supply Chain Security#153

Open
piiiico wants to merge 1 commit into
devsecops:masterfrom
piiiico:add-proof-of-commitment
Open

Add Proof of Commitment to Supply Chain Security#153
piiiico wants to merge 1 commit into
devsecops:masterfrom
piiiico:add-proof-of-commitment

Conversation

@piiiico

@piiiico piiiico commented Jun 12, 2026

Copy link
Copy Markdown

Adds Proof of Commitment to the Supply Chain Security section.

What it does: Scores npm, PyPI, Cargo and Go packages on behavioral commitment signals — publisher depth, release consistency, maintenance patterns — that predict supply chain risk before attacks happen. Both axios and chalk scored CRITICAL before their 2026 compromises.

How it ships:

  • CLI (npx proof-of-commitment)
  • MCP server (Claude Desktop, Cursor)
  • GitHub Action (piiiico/commit-action)
  • IDE hooks for Cursor, Claude Code and Windsurf (poc hook)

Different from existing entries: operates on behavioral signals rather than vulnerability databases (Snyk/Dependabot) or build-time integrity (Sigstore/Preflight).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant