Checkmarx / ast-cli
A CLI project wrapping application security testing (AST) APIs
☆50Updated this week
Alternatives and similar repositories for ast-cli:
Users that are interested in ast-cli are comparing it to the libraries listed below
- Checkmarx Scan and Result Orchestration☆94Updated this week
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use …☆66Updated 10 months ago
- The Open Security Summit is focused on the collaboration between, Developers and Application Security☆45Updated 3 months ago
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.☆37Updated 3 years ago
- OWASP Kubernetes Security Testing Guide☆37Updated 7 months ago
- StartLeft is an automation tool for generating Threat Models written in the Open Threat Model (OTM) format from a variety of different so…☆50Updated last week
- ☆60Updated 2 months ago
- A project to visualize the software supply chain☆45Updated last year
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆62Updated 9 months ago
- NextJS-based single-page application for completing and reviewing SAMM assessments☆72Updated 2 years ago
- Checkmarx Python SDK☆28Updated last week
- Awesome Snyk community contributions, champions, integrations, blogs, tools and more 💜☆47Updated 3 years ago
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain☆92Updated 2 months ago
- Discover vulnerabilities and container image misconfiguration in production environments.☆55Updated last month
- OWASP Foundation Threat Dragon Project Web Repository☆79Updated this week
- OWASP Foundation Web Respository☆28Updated 7 months ago
- A full insecure kubernetes application for testing security tools☆70Updated last week
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆107Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆171Updated 4 months ago
- Exports vulnerability scan data from the Checkmarx SAST platform for use in analytical tools.☆19Updated 5 months ago
- An open project to list all publicly known cloud vulnerabilities and CSP security issues☆336Updated last week
- The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously…☆206Updated 2 months ago
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.☆99Updated last year
- The source files and tools needed to build the OWASP Cornucopia decks in various languages☆61Updated this week
- ☆35Updated 3 years ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and vers…☆114Updated last month
- A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.☆188Updated last year
- Threat Modeling Manifesto☆28Updated 8 months ago
- Dependency Combobulator☆93Updated last year
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆132Updated last year