Use Case
Software Supply Chain Security
Securing dependencies, builds, and artifacts.
16 providers
110 APIs
11 declared variants
Knowing and trusting what goes into a build — dependency inventory, SBOMs, license checks, artifact signing, and provenance across the release pipeline.
16 API providers on the APIs.io network offer software supply chain security. The highest-rated are GitHub, Anchore, Aqua Security, Amazon CodeArtifact, Livepeer.
Providers
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Strong 4 Solid coverage with minor gaps
GitHub
The GitHub REST API allows developers to programmatically interact with GitHub resources including reposito...
Anchore
Anchore is a container and software supply chain security company providing open source and enterprise tool...
Aqua Security
Aqua Security provides cloud-native security for the full application lifecycle, protecting containers, ser...
Amazon CodeArtifact
Amazon CodeArtifact is a fully managed, secure artifact repository service that helps organizations store, ...
Developing 2 Usable, with meaningful gaps to close
Thin 7 Limited public surface area
Application Research
Application Research is a topic collection focused on specifications for declaring application service inte...
Ansible Roles
A curated collection of APIs and resources for discovering, managing, and consuming Ansible roles — the pri...
Zero Trust Architecture
Zero Trust Architecture (ZTA) is a security framework defined by NIST SP 800-207 that requires all users an...
YARN
YARN (Yet Another Resource Negotiator in the original Hadoop context; also the JavaScript package manager) ...
Artifact Hub
Artifact Hub is a CNCF incubating web-based application that enables finding, installing, and publishing cl...
Chainguard
Chainguard builds, secures, and maintains a catalog of hardened, minimal container images and software supp...
Apache Ant
Apache Ant is a Java-based build tool and library developed by the Apache Software Foundation, used to auto...
Emerging 3 Early or largely undocumented
Certero
Certero is an enterprise IT Asset Management (ITAM) software vendor whose flagship CerteroX platform unifie...
CHAOSS
CHAOSS (Community Health Analytics in Open Source Software) is a Linux Foundation project that develops met...
Apache Maven
Apache Maven is a software project management and comprehension tool based on the concept of a project obje...
What Providers Actually Declared
This use case is a canonical term. These are the free-text strings
providers wrote in their own apis.yml that map onto it.
Dependency ManagementDependency Management with IvyGenerate SBOMs for software supply chain transparencyLicense ComplianceOpen Source Risk and Security AssessmentPackage PublishingSBOM GenerationSoftware License ComplianceSoftware Supply Chain SecuritySupply Chain SecurityWeb3 / NFT video drops with on-chain provenance
Scroll for all 11