Add proof-of-commitment — behavioral supply chain risk scoring#106
Open
piiiico wants to merge 1 commit into
Open
Add proof-of-commitment — behavioral supply chain risk scoring#106piiiico wants to merge 1 commit into
piiiico wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this adds
proof-of-commitment (github.com/piiiico/proof-of-commitment) — behavioral risk scoring for npm, PyPI, Rust, and Go packages.
Added to Supply chain specific tools section.
Why it belongs here
Most supply chain tools focus on known CVEs or SBOM generation. proof-of-commitment surfaces a different class of risk: behavioral anomalies that appear before a vulnerability is catalogued.
Key signals it scores:
npm auditdoesn't surface this.Available as MCP server (no login required), CLI (
npx proof-of-commitment), GitHub Action, and web UI at getcommit.dev.Format
Follows the existing table format used in this section.