SpectralOps / spectral-github-actionLinks
Spectral Security Integration into your Github Actions pipeline
☆15Updated last year
Alternatives and similar repositories for spectral-github-action
Users that are interested in spectral-github-action are comparing it to the libraries listed below
Sorting:
- Monitor your code for exposed API keys, tokens, credentials, and high-risk security IaC misconfigurations☆19Updated 2 years ago
- preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.☆156Updated 2 years ago
- A catalog of SaaS APIs and their security levels, compliance, and regulation like GDPR, ISO27001, PCI and others☆128Updated 4 years ago
- Evaluate source control (GitHub) security posture☆251Updated 2 years ago
- An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchm…☆762Updated 10 months ago
- The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.☆891Updated last year
- GitHub Advanced Security Policy as Code☆90Updated 3 weeks ago
- GitGoat is an open source tool that was built to enable DevOps and Engineering teams to design and implement a sustainable misconfigurati…☆170Updated 9 months ago
- Orchestrate GitHub Actions Security☆300Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆905Updated last week
- A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles☆543Updated 5 months ago
- Anchore container analysis and scan provided as a GitHub Action☆256Updated last week
- GitHub Action for creating software bill of materials using Syft.☆208Updated 2 weeks ago
- Open source compliance tool for development platforms.☆288Updated 2 years ago
- Official GitHub Action for OpenSSF Scorecard.☆339Updated this week
- ☆285Updated 2 years ago
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets☆816Updated 7 months ago
- Terrascan GitHub action. Scan infrastructure as code including Terraform, Kubernetes, Helm, and Kustomize file for security best practice…☆63Updated 10 months ago
- ValidIaC combines the best open-source tools to help ensure Infrastructure-as-Code best practices, hygiene & security.☆233Updated 6 months ago
- Generate SBOMs with gh CLI☆195Updated 5 months ago
- A reading list for software supply-chain security.☆365Updated 2 years ago
- Language-agnostic SLSA provenance generation for Github Actions☆515Updated 2 weeks ago
- Notice: Postee is no longer under active development or maintenance.☆208Updated 2 months ago
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆589Updated 7 months ago
- Enrich SBOMs with data from third party services☆196Updated 2 months ago
- ☆20Updated 2 years ago
- Identity & Access Management simplified and secure.☆260Updated 2 years ago
- A set of GitHub actions for checking your projects for vulnerabilities.☆603Updated last month
- Useful scripts, Docker images, docker-compose apps, and Terraform modules.☆151Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆234Updated last year