cdfoundation / CICD-Cybersecurity
CI/CD pipelines are critical touchpoints in modern software development where code-level vulnerabilities, container security, and vulnerability remediation efforts converge. This SIG is dedicated to advancing security tooling within CI/CD pipelines, with a focus on defining best security practices and developing frameworks for secure pipeline.
☆12Updated 3 weeks ago
Alternatives and similar repositories for CICD-Cybersecurity:
Users that are interested in CICD-Cybersecurity are comparing it to the libraries listed below
- SIG Software Supply Chain☆16Updated 5 months ago
- This is the source repository for https://bestpractices.cd.foundation☆14Updated last year
- Instructions and scripts how to deploy Keptn on K3s☆29Updated 2 years ago
- Contains every things needed to release jenkins core from the jenkins infra project☆17Updated this week
- Docker Scout GitHub Action☆109Updated last week
- Github Action to automatically update digests for container images.☆57Updated last month
- Check SPDX SBOM for NTIA minimum elements☆62Updated 3 weeks ago
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- A tool to create, transform and attest VEX metadata☆134Updated this week
- Docker images using large file support for binary files☆26Updated this week
- 📜Fork for tracking CNCF projects☆56Updated last week
- A collection of information from people working on and with Tekton.☆44Updated last year
- Docs and Tutorials for Chainguard☆83Updated this week
- CDF Events Special Interest Group☆51Updated 5 months ago
- GitHub actions of KICS scan - Keeping Infrastructure as Code Secure☆48Updated last month
- Sources used for the Buoyant Service Mesh Academy, for your entertainment and knowledge, and as a base for getting things done.☆72Updated last month
- Scenario examples for Killercoda.com☆109Updated 8 months ago
- Documentation for users of Jenkins project infrastructure☆23Updated last week
- Policy Reporter Kyverno Plugin☆14Updated 8 months ago
- Documents and tools powering the Wolfi OS community☆20Updated last year
- Jenkins Infrastructure Kubernetes Management☆59Updated this week
- Github action to generate BoM and upload to OWASP dependency track for vulnerability analysis☆41Updated 7 months ago
- Kyverno for any JSON!☆85Updated 3 months ago
- ☆10Updated 4 years ago
- Start securing your secrets and infrastructure by installing Conjur, using Docker and the official Conjur containers on DockerHub.☆35Updated last week
- GitHub Action for Copacetic: Directly patch container image vulnerabilities☆26Updated last year
- ☆21Updated last year
- GitHub Action for creating software bill of materials using Syft.☆180Updated 3 weeks ago
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- The Aqua Security Provider for Terraform allows you to declaratively define the configuration of your Aqua platform.☆37Updated 3 weeks ago