aquasecurity / vexhub
☆20Updated last week
Alternatives and similar repositories for vexhub:
Users that are interested in vexhub are comparing it to the libraries listed below
- ☆46Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- An SBOM query language and associated utilities☆54Updated last year
- A tool to create, transform and attest VEX metadata☆133Updated this week
- Slack alert bot for matching Github Audit Events☆10Updated 4 months ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆80Updated 2 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- Protect GitHub Actions with Tracee☆80Updated last month
- Kubernetes audit logging, when you don't control the control plane☆71Updated this week
- Cloud Security Posture security policies☆29Updated 6 months ago
- Format agnostic SBOM tooling☆102Updated last week
- ☆112Updated 2 months ago
- Check SPDX SBOM for NTIA minimum elements☆60Updated last week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- A VS Code Extension for Trivy☆122Updated this week
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated 3 months ago
- ☆53Updated last week
- Manage a uniform team of security managers for every organization in your enterprise☆17Updated 7 months ago
- ☆18Updated this week
- ☆16Updated 10 months ago
- Run individual controls or full compliance benchmarks for NSA CISA Kubernetes Hardening Guidance across all of your Kubernetes clusters u…☆32Updated 5 months ago
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆80Updated this week
- CLI to prevent malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions…☆85Updated this week
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆88Updated this week
- ☆61Updated 8 months ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆74Updated last week
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- ☆40Updated 4 months ago