SecureStackCo / actions-sbomLinks
A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, staging and prod steps and SecureStack will make sure that what you've just deployed is secure and meets your requirements, and has the SBOM to show it!
☆25Updated 2 years ago
Alternatives and similar repositories for actions-sbom
Users that are interested in actions-sbom are comparing it to the libraries listed below
Sorting:
- A tool to check the security settings of Github Organizations.☆75Updated 2 years ago
- Clean accounts over permissions in GCP infra at scale☆71Updated 2 years ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated 2 years ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated 2 years ago
- Compares and analyzes GCP IAM roles.☆77Updated 9 months ago
- ☆114Updated 2 years ago
- 🖇️ equivalence table between OWASP ASVS standard and STRIDE threat modeling methodology.☆75Updated last year
- ☆114Updated 4 months ago
- Protect against subdomain takeover☆95Updated 5 months ago
- Scans your Github Actions for security issues☆88Updated last month
- An open-source collection of API key rotation tutorials.☆76Updated 3 months ago
- ☆56Updated 2 weeks ago
- Scans every git push to your Github organisations to find unwanted secrets.☆87Updated 7 months ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆177Updated 2 weeks ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆68Updated 6 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆156Updated last year
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆114Updated this week
- 💅🏽 analyzes your github actions☆97Updated 3 months ago
- ## Auto-archived due to inactivity. ## Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Securit…☆37Updated last year
- ☆75Updated 2 months ago
- ☆131Updated last week
- Convert cloudtrail data to MITRE ATT&CK Sightings☆82Updated 3 years ago
- ☆49Updated 2 years ago
- GCP CSPM using Google Sheets☆37Updated 8 months ago
- https://breaches.cloud☆42Updated last year
- SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context P…☆132Updated 6 months ago
- sgCheckup generates nmap output based on scanning your AWS Security Groups for unexpected open ports.☆81Updated 4 years ago
- The security workflow engine!☆136Updated last month
- A small tool to help developers understand a huge set of security requirements from appsec teams☆47Updated 3 years ago
- A tool to uncover undocumented APIs from the AWS Console.☆115Updated 8 months ago