Eclipse SCINTX (Supply Chain Intelligence Exchange)

Eclipse SCINTX (Supply Chain Intelligence Exchange) is a vendor-neutral open standard and reference implementation for package-security integration. It sits between package registries / CI systems and security providers. Users submit package artifacts (e.g. by PURL and digests). The gateway assesses them via pluggable providers, evaluates consumer policy, and returns portable decisions and findings. Outcomes can be delivered by polling or signed CloudEvents webhooks; consumers may adjudicate review decisions and share the final allow/deny gate back to the gateway.


The goal is to eliminate duplicated registry–vendor integrations, make security verdicts comparable and portable, and let registries and enterprises mix-and-match conforming providers without lock-in.

State
Incubating
Licenses
Eclipse Public License 2.0

The content of this open source project is received and distributed under the license(s) listed above. Some source code and binaries may be distributed under different terms. Specific license information is provided in file headers and in NOTICE files distributed with the project's binaries.

Active Member Companies

Member companies supporting this project over the last three months.

    Is your logo missing?