SecureStackCo / actions-sbomLinks
A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure and meets your requirements, and has the SBOM to show it!
☆25Updated 2 years ago
Alternatives and similar repositories for actions-sbom
Users that are interested in actions-sbom are comparing it to the libraries listed below
Sorting:
- Clean accounts over permissions in GCP infra at scale☆71Updated 2 years ago
- Compares and analyzes GCP IAM roles.☆77Updated 7 months ago
- A tool to check the security settings of Github Organizations.☆72Updated 2 years ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆42Updated 2 years ago
- ☆10Updated 3 years ago
- ☆114Updated 2 years ago
- ☆115Updated 2 months ago
- ☆56Updated last month
- Protect against subdomain takeover☆94Updated 3 months ago
- 🖇️ STRIDE vs. ASVS equivalence table☆77Updated last year
- Semgrep-based Policy Controller for Kubernetes☆47Updated 6 months ago
- Scans every git push to your Github organisations to find unwanted secrets.☆87Updated 5 months ago
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆34Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆177Updated 11 months ago
- This application was built to help reduce the amount of time it takes to review AWS Lambda code.☆61Updated 11 months ago
- ☆73Updated this week
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆67Updated 4 months ago
- The security workflow engine!☆126Updated last week
- Collection of incidents resulting from caching issues☆29Updated 4 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆156Updated last year
- Data about all known supply-chain attacks through history☆60Updated 4 months ago
- SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context P…☆133Updated 4 months ago
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆61Updated last week
- Convert cloudtrail data to MITRE ATT&CK Sightings☆80Updated 3 years ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆127Updated 8 months ago
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆138Updated 2 weeks ago
- TrailAlerts is a AWS-native, serverless cloud-detection tool that lets you define simple rules as code and get rich alerts about events i…☆51Updated 5 months ago
- ☆49Updated 2 years ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆112Updated last week
- ☆14Updated 3 years ago