anchore / scan-actionLinks
Anchore container analysis and scan provided as a GitHub Action
☆250Updated last week
Alternatives and similar repositories for scan-action
Users that are interested in scan-action are comparing it to the libraries listed below
Sorting:
- GitHub Action for creating software bill of materials using Syft.☆191Updated last week
- Language-agnostic SLSA provenance generation for Github Actions☆485Updated 2 weeks ago
- Verify provenance from SLSA compliant builders☆271Updated 2 weeks ago
- A utility to generate SPDX-compliant Bill of Materials manifests☆399Updated this week
- Cosign Github Action☆149Updated last week
- Official GitHub Action for OpenSSF Scorecard.☆316Updated this week
- A tool to create, transform and attest VEX metadata☆146Updated 2 weeks ago
- A collection of reusable Github Actions workflows.☆133Updated last week
- A GitHub action to help you scan your docker image for vulnerabilities☆221Updated 2 years ago
- ☆240Updated last week
- A CLI tool to sign and verify artifacts☆414Updated last week
- Plugin for Docker CLI to support SBOM creation using Syft☆157Updated 3 months ago
- Orchestrate GitHub Actions Security☆291Updated last week
- Search an SBOM for licenses and the packages they belong to☆94Updated last week
- Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities☆999Updated last week
- Evaluate source control (GitHub) security posture☆250Updated 2 years ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 2 years ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆488Updated last week
- Regal is a linter and language server for Rego, bringing your policy development experience to the next level!☆315Updated last week
- in-toto Attestation Framework☆280Updated 3 weeks ago
- Cross tooling and interoperability specifications☆173Updated last month
- Generate SBOMs with gh CLI☆189Updated last month
- Style guide for Rego☆201Updated 3 months ago
- A Github Action to automatically update digests for container images.☆66Updated last month
- GitHub actions of KICS scan - Keeping Infrastructure as Code Secure☆49Updated last week
- Publishes BOMs to Dependency-Track from GitHub Actions☆54Updated 9 months ago
- Open source compliance tool for development platforms.☆286Updated last year
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆50Updated last year
- An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster☆457Updated this week
- Enrich SBOMs with data from third party services☆178Updated 3 months ago