IBM / detect-secrets
An enterprise friendly way of detecting and preventing secrets in code.
☆79Updated 8 months ago
Alternatives and similar repositories for detect-secrets:
Users that are interested in detect-secrets are comparing it to the libraries listed below
- Security configuration checks for popular cloud native applications and infrastructure.☆118Updated 3 years ago
- ☆16Updated 2 years ago
- All Aqua deployments options and aquactl configuration☆58Updated last week
- ☆27Updated 2 weeks ago
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated last year
- Trivy's misconfiguration scanning engine☆216Updated 2 months ago
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.☆98Updated last year
- ☆51Updated this week
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 3 years ago
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆92Updated this week
- DEPRECATED: A set of utilities for converting and working with compliance data for viewing in the heimdall applications☆35Updated 3 years ago
- The Auditree data gathering and reporting tool.☆13Updated 7 months ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆73Updated 11 months ago
- Owasp Zap chart for Kubernetes☆50Updated 3 years ago
- GitHub Action for creating software bill of materials using Syft.☆175Updated last week
- A community collection of security reviews of open source software components.☆93Updated last year
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- Sample code snippets for consuming the CloudSploit API☆13Updated last year
- a tool to audit the istio service mesh☆173Updated 3 years ago
- ☆10Updated 2 years ago
- Test and monitor your projects for vulnerabilities with Jenkins. This plugin is officially maintained by Snyk.☆60Updated 7 months ago
- OWASP Kubernetes Security Testing Guide☆37Updated 6 months ago
- ☆93Updated last month
- ☆12Updated 3 years ago
- Docker Secure Computing Profile Generator☆48Updated 3 years ago
- Application Security Workflow Automation using Docker and Kubernetes☆22Updated 2 years ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆40Updated this week
- PCI-DSS v4.0 Control Baseline for Red Hat Enterprise Linux 7 - Ansible role generated from ComplianceAsCode Project☆29Updated last year
- List of all previous CNCF Project's Security Audit Reports☆38Updated 4 years ago