blackducksoftware / github-action
Synopsys Detect integration with Github Actions
☆17Updated last year
Alternatives and similar repositories for github-action:
Users that are interested in github-action are comparing it to the libraries listed below
- This plugin provides dependency metadata for Docker images☆34Updated last week
- Checkmarx CxFlow GitHub Action with SARIF output☆53Updated 2 months ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆84Updated last month
- GitHub Secret Scanning Auto Remediator (GSSAR)☆44Updated last year
- OWASP Foundation Web Respository☆28Updated 7 months ago
- Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning …☆41Updated 9 months ago
- Website and API for OpenSSF Scorecard☆23Updated this week
- This repository contains a sample script which can be used to enable security vulnerability alerts in all of the repositories in a given …☆80Updated 5 months ago
- Exports vulnerability scan data from the Checkmarx SAST platform for use in analytical tools.☆19Updated 4 months ago
- Technical Advisory Council☆118Updated last week
- ☆34Updated 7 months ago
- Report missing advisories and corrections on OSS Index☆17Updated 2 years ago
- Examples of SPDX files for software combinations☆128Updated 2 months ago
- Prevent leaks with gitleaks, and use tests to validate☆32Updated 3 months ago
- Examples and proof-of-concept for Software Bill of Materials (SBOM) code & data☆57Updated 11 months ago
- Test and monitor your projects for vulnerabilities with Jenkins. This plugin is officially maintained by Snyk.☆60Updated 6 months ago
- OpenSSF Governance and Legal Docs☆72Updated 2 months ago
- GitHub Advance Security Compliance Action☆132Updated 2 years ago
- CVE database☆22Updated 4 years ago
- FedRAMP Tailored.☆43Updated 3 years ago
- ☆79Updated 10 months ago
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆92Updated this week
- Awesome Snyk community contributions, champions, integrations, blogs, tools and more 💜☆47Updated 3 years ago
- OpenSSF Endusers Working Group☆28Updated last year
- The GCP PubSec Declarative Toolkit is a collection of declarative solutions to help you on your Journey to Google Cloud. Solutions are de…☆34Updated 2 weeks ago
- SLSA Azure DevOps Pipelines Extension☆26Updated 7 months ago
- SPDX Command Line Tools using the Spdx-Java-Library☆67Updated 3 weeks ago
- A broker system between a public service and a private service☆106Updated last week
- Actions and Images for use in Learning Lab courses for CodeQL☆35Updated 2 years ago
- Scanning and analysis for Black Duck SCA products.☆170Updated this week