SecureStackCo / actions-sbomLinks
A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure and meets your requirements, and has the SBOM to show it!
☆25Updated 2 years ago
Alternatives and similar repositories for actions-sbom
Users that are interested in actions-sbom are comparing it to the libraries listed below
Sorting:
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated 2 years ago
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 10 months ago
- Scans every git push to your Github organisations to find unwanted secrets.☆87Updated 2 months ago
- Compares and analyzes GCP IAM roles.☆77Updated 4 months ago
- A security tool designed to help review merged code changes to open source maintained repositories via LLM assisted review to safeguard a…☆30Updated 8 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated last year
- A tool to check the security settings of Github Organizations.☆71Updated 2 years ago
- Clean accounts over permissions in GCP infra at scale☆71Updated 2 years ago
- Protect against subdomain takeover☆92Updated last year
- ☆55Updated 2 weeks ago
- ☆111Updated 2 years ago
- ☆113Updated last week
- ☆10Updated 3 years ago
- ☆14Updated 3 years ago
- ☆116Updated this week
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆31Updated 9 months ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆173Updated 7 months ago
- ☆70Updated last month
- Repository to archive GCP Documentation for local use☆16Updated 5 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆156Updated 10 months ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated last week
- ☆34Updated 2 months ago
- GCP CSPM using Google Sheets☆36Updated 3 months ago
- ☆66Updated 2 years ago
- Semgrep-based Policy Controller for Kubernetes☆47Updated 3 months ago
- Knowledge Report Alert & Normalization Generator☆27Updated last year
- The security workflow engine!☆118Updated this week
- Audit log wall of shame.☆41Updated 9 months ago
- ☆12Updated 3 weeks ago
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.☆38Updated 3 years ago