ShiftLeftSecurity / scan-action
☆53Updated 2 years ago
Alternatives and similar repositories for scan-action:
Users that are interested in scan-action are comparing it to the libraries listed below
- A broker system between a public service and a private service☆106Updated this week
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- Run a security scan on your terraform with the very nice https://github.com/aquasecurity/tfsec☆112Updated 5 months ago
- GitHub Secret Scanning Auto Remediator (GSSAR)☆44Updated last year
- Generate a score for your sbom to understand if it will actually be useful.☆226Updated 7 months ago
- GitHub Advance Security Compliance Action☆133Updated 2 years ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 months ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- GitHub Action for creating software bill of materials using Syft.☆176Updated last week
- Sysdig Terraform provider. Allow to handle Sysdig Secure policies as code.☆52Updated this week
- ☆79Updated 11 months ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆73Updated 11 months ago
- Present ZAProxy results in GitHub Advanced Security☆16Updated 10 months ago
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 9 months ago
- Agile Threat Modeling as Code☆13Updated 2 years ago
- Publishes BOMs to Dependency-Track from GitHub Actions☆52Updated 5 months ago
- Github action to benchmark dockerfiles in github repository.☆12Updated 2 years ago
- Git action to generate security lint report for Kubernetes workload YAML files on PR☆28Updated 3 years ago
- A tool to create, transform and attest VEX metadata☆133Updated this week
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated 3 months ago
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Go library for sarif - Static Analysis Results Interchange Format☆72Updated last week
- Inline Image Scan Github Action☆30Updated last month
- Synchronize GitHub Code Scanning alerts to Jira issues☆84Updated last month
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆16Updated this week
- Run tfsec with reviewdog on pull requests to enforce security best practices☆74Updated this week
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 3 years ago
- ☆56Updated 2 years ago
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆48Updated last year