11/12 free views
Tool
Web Service
Governance, Risk, and Compliance (GRC)

guac

by guacsec

1.4Kstars
187forks
43watchers
Updated 8 months ago
About

GUAC aggregates and normalizes software security metadata into a high fidelity graph database to enable comprehensive supply chain transparency and risk management.

GUAC aggregates software security metadata into a high fidelity graph database.

Primary Use Case

GUAC is used by security teams, auditors, and developers to aggregate diverse software supply chain metadata into a unified graph, enabling risk assessment, compliance auditing, and security automation. It helps organizations query and analyze software artifact relationships to improve governance, risk management, and compliance efforts.

Key Features
  • Aggregates software security metadata into a graph database
  • Normalizes entity identities and maps standard relationships
  • Supports multiple input document formats like CycloneDX, SPDX, SLSA, OSV, and more
  • Provides a consistent GraphQL API with pluggable backend support
  • Enables audit, policy enforcement, risk management, and developer assistance
  • OpenSSF incubating project focused on supply chain integrity
  • Includes demos and use cases for quick adoption
  • Docker Compose quickstart for easy deployment

Installation

  • Visit https://docs.guac.sh/ for detailed documentation
  • Start GUAC services using the docker compose quickstart available at https://docs.guac.sh/setup/
  • Refer to the contributor guide (CONTRIBUTING.md) for development setup

Usage

>_ docker compose up

Starts the GUAC services using the provided Docker Compose configuration

Security Frameworks
Reconnaissance
Resource Development
Collection
Defense Evasion
Discovery
Usage Insights
  • Integrate GUAC with CI/CD pipelines to automate supply chain risk assessments and enforce compliance policies before deployment.
  • Leverage GUAC's graph database to visualize and trace software component relationships for faster incident investigation and root cause analysis.
  • Use GUAC's normalized metadata to enhance threat hunting by correlating supply chain artifacts with known vulnerabilities and exposures.
  • Combine GUAC with vulnerability management tools to prioritize patching based on software supply chain risk context.
  • Employ GUAC in purple team exercises to simulate supply chain attacks and validate detection and response capabilities across development and security teams.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about guac. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

This tool hasn't been indexed yet. Request indexing to enable AI chat.

Admin will review your request within 24 hours

Security Profile
Red Team30%
Blue Team90%
Purple Team70%
Details
LicenseApache License 2.0
LanguageGo
Open Issues512
Topics
security
software-supply-chain
software-supply-chain-security
supply-chain
supply-chain-security
supply-chain-visibility
supply-chain-analytics
attestations
graph
sbom