Skip to content

nodealchemy/powernode-supply-chain

Powernode Supply Chain Extension

Software supply chain security for Powernode: SBOM management, vulnerability scanning, container security, attestations, vendor risk, and license compliance — wired into the Powernode platform via the extension contract.

This repository is mounted into the platform as a submodule at extensions/supply-chain/. It can be developed independently — the platform consumes it via the standard extension contract.


What this extension provides

  • SBOM management — generate, store, and query software bill of materials for every module + container in the fleet
  • Vulnerability scanning — identify CVEs across dependencies + container images, with severity scoring + exploitability context
  • Container security — image signature verification, runtime policy enforcement, attestation cross-checks at attach time
  • Attestations — cryptographic provenance records (SLSA, in-toto) generated at build + verified at install
  • Vendor risk — third-party supplier risk scoring with configurable inputs
  • License compliance — track + flag license obligations across dependencies; surface conflicts before they ship

Requirements

A running Powernode platform installation. See the parent platform repo for installation instructions.


Layout

extensions/supply-chain/
├── server/                 # Rails models, services, controllers, specs
├── frontend/               # React TypeScript surface
├── worker/                 # Sidekiq job classes
└── docs/                   # Extension documentation

License

MIT — see LICENSE. Code of Conduct: see CODE_OF_CONDUCT.md.


Community

Text channels

Email


Related

About

Powernode supply-chain extension — logistics, supply chain management, SBOM workflows (MIT)

Topics

Resources

License

Code of conduct

Contributing

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors