SecureStackCo / actions-sbomLinks
A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure and meets your requirements, and has the SBOM to show it!
☆25Updated 2 years ago
Alternatives and similar repositories for actions-sbom
Users that are interested in actions-sbom are comparing it to the libraries listed below
Sorting:
- Clean accounts over permissions in GCP infra at scale☆71Updated 2 years ago
- Compares and analyzes GCP IAM roles.☆77Updated 5 months ago
- A tool to check the security settings of Github Organizations.☆72Updated 2 years ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated 2 years ago
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 11 months ago
- Scans every git push to your Github organisations to find unwanted secrets.☆87Updated 3 months ago
- ☆10Updated 3 years ago
- ☆112Updated 2 years ago
- A security tool designed to help review merged code changes to open source maintained repositories via LLM assisted review to safeguard a…☆30Updated 9 months ago
- ☆56Updated 2 weeks ago
- The security workflow engine!☆119Updated this week
- Protect against subdomain takeover☆92Updated 2 weeks ago
- A project to visualize the software supply chain☆52Updated last year
- A public cloud security knowledgebase - https://www.secwiki.cloud/☆51Updated 8 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆155Updated 11 months ago
- ☆70Updated last week
- ☆119Updated this week
- ☆66Updated 3 weeks ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆174Updated 8 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆80Updated 3 years ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated 2 weeks ago
- 💅🏽 analyzes your github actions☆93Updated last month
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆66Updated last month
- GCP CSPM using Google Sheets☆36Updated 4 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated last year
- ☆113Updated 2 weeks ago
- ☆12Updated last month
- A tool for preventing the installation of malicious npm and PyPI packages☆153Updated this week
- SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context P…☆80Updated 2 months ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆108Updated last year