SecureStackCo / actions-sbom
A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure and meets your requirements, and has the SBOM to show it!
☆24Updated last year
Alternatives and similar repositories for actions-sbom:
Users that are interested in actions-sbom are comparing it to the libraries listed below
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 8 months ago
- Clean accounts over permissions in GCP infra at scale☆71Updated last year
- Compares and analyzes GCP IAM roles.☆77Updated last month
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated last year
- ☆54Updated this week
- SecureStack Application Bill of Materials (ABOM/SBOM)☆13Updated 2 years ago
- A project to visualize the software supply chain☆50Updated last year
- Protect against subdomain takeover☆92Updated 11 months ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Updated 4 months ago
- A small tool to help developers understand a huge set of security requirements from appsec teams☆45Updated 2 years ago
- A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity program☆15Updated this week
- ☆112Updated 3 months ago
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆63Updated 10 months ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- ☆10Updated 2 years ago
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆31Updated 6 months ago
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.☆37Updated 3 years ago
- A CLI that scans for sensitive data in source code☆14Updated 2 years ago
- ☆110Updated last year
- Semgrep-based Policy Controller for Kubernetes☆47Updated last month
- Maturity Model Collaborative project☆15Updated 2 years ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆41Updated last year
- AI featured threat modeling and security review action☆43Updated 5 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆80Updated 2 years ago
- ☆63Updated 2 years ago
- Unauthenticated enumeration of AWS IAM Roles.☆24Updated 3 months ago
- GCP CSPM using Google Sheets☆35Updated last month
- All of our GitHub Actions rolled into one. Or as we like to say: One GitHub Action to rule them all!☆21Updated last year