Skip to content
Back to the index

vamp-supply-chain

PyPIInfrastructure

PulseGate's liveness check found it on 28 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 28 Sep 2026. How this is checked

vamp-supply-chain is a command-line security scanner for software supply chains. It generates SBOMs, checks dependencies for CVEs, detects typosquatting, and verifies package checksums for developers and security teams.

Inferred · not functionally tested

AGPL-3.0-onlyCLISelf-hosted
Visit PyPI

Overview

5 features

Purpose: Detecting vulnerabilities and integrity risks in software dependencies and supply chains.

Inferred · not functionally tested

Audience: DevSecOps engineers and software developers

Inferred · not functionally tested

Functions: data_extraction

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: unknown · license: AGPL-3.0-only · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

vamp-supply-chain sits in PulseGate's Application security & vulnerability scanning category. Inferred · not functionally tested: It focuses on detecting vulnerabilities and integrity risks in software dependencies and supply chains. Inferred · not functionally tested: It is built as an open-source project for devSecOps engineers and software developers. Basis unknown · not verified: It runs on the command line, and it can be self-hosted.

Behind vamp-supply-chain is Vampsecure Labs, and it first shipped in 2026. Inferred · not functionally tested: Key capabilities include SBOM generation, CVE checks, and typosquatting detection.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • SBOM generation
  • CVE checks
  • Typosquatting detection
  • Checksum verification
  • Dependency scanning

Topics: Inferred · not functionally tested

Tags
supply-chain-securitysbom-generationtyposquatting-detectioncve-scanning

JSON profile · Text profile · Access guide

Built with & integrations

Runs on
CLISelf-hosted

Trust & compliance

License
AGPL-3.0-only
Public signals
HTTPSGitHub

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed28 Sep · 11:48 UTC
    vamp-supply-chain seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about vamp-supply-chain

What is vamp-supply-chain?
Inferred · not functionally tested: Vamp-supply-chain focuses on detecting vulnerabilities and integrity risks in software dependencies and supply chains. It is catalogued under Application security & vulnerability scanning on PulseGate.
Who should use vamp-supply-chain?
Inferred · not functionally tested: vamp-supply-chain is an open-source project built for devSecOps engineers and software developers.
What platforms does vamp-supply-chain run on?
Basis unknown · not verified: vamp-supply-chain runs on the command line. It can also be self-hosted.
Is vamp-supply-chain still active?
PulseGate's liveness check found it on 28 Sep 2026.
What are alternatives to vamp-supply-chain?
Similar projects tracked by PulseGate include vamp-secrets-scanner, devinder-supply-chain-scanner, and vamp-compliance-check.vamp-secrets-scannerdevinder-supply-chain-scannervamp-compliance-check
Who makes vamp-supply-chain?
vamp-supply-chain is developed by Vampsecure Labs.
When did vamp-supply-chain launch?
vamp-supply-chain first shipped in 2026.
Is vamp-supply-chain open source?
Basis unknown · not verified: vamp-supply-chain has a public GitHub repository.

Similar projects

Closest matches by what these projects do