cdfoundation / CICD-Cybersecurity
CI/CD pipelines are critical touchpoints in modern software development where code-level vulnerabilities, container security, and vulnerability remediation efforts converge. This SIG is dedicated to advancing security tooling within CI/CD pipelines, with a focus on defining best security practices and developing frameworks for secure pipeline.
☆14Updated this week
Alternatives and similar repositories for CICD-Cybersecurity
Users that are interested in CICD-Cybersecurity are comparing it to the libraries listed below
Sorting:
- SIG Software Supply Chain☆16Updated 5 months ago
- This is the source repository for https://bestpractices.cd.foundation☆14Updated last year
- Docs and Tutorials for Chainguard☆83Updated this week
- Global Cyber Policy Working Group☆56Updated this week
- CDF Interoperability SIG☆65Updated 5 months ago
- Check SPDX SBOM for NTIA minimum elements☆61Updated 2 weeks ago
- Workshops for CloudBees CI, CloudBees CD/RO, and CloudBees Feature Management.☆15Updated 8 months ago
- Start securing your secrets and infrastructure by installing Conjur, using Docker and the official Conjur containers on DockerHub.☆35Updated last week
- CLI tool for generating reports on Kubernetes workloads.☆20Updated last month
- Terraform provider for provisioning Harness resources☆40Updated this week
- Docker Scout GitHub Action☆114Updated this week
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆79Updated 6 months ago
- Contains every things needed to release jenkins core from the jenkins infra project☆17Updated this week
- CNCF TechDocs Team☆49Updated 3 weeks ago
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆16Updated last week
- Instructions and scripts how to deploy Keptn on K3s☆29Updated 2 years ago
- Documentation and guidance for handling outbound open source for organizations☆21Updated 2 years ago
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- Keptn community content: governance, community management, project infrastructure etc.☆53Updated 2 months ago
- GitHub Action for Copacetic: Directly patch container image vulnerabilities☆28Updated last year
- GitHub app for SBOM creation using cdxgen and upload to Dependency-Track☆18Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆92Updated this week
- 📈CNCF-created tool for analyzing and graphing developer contributions☆94Updated this week
- CNCF Project Template☆70Updated 9 months ago
- ☆84Updated this week
- Github Action to automatically update digests for container images.☆58Updated last month
- ☆11Updated 7 months ago
- OSPO Landscape☆37Updated 3 weeks ago
- Terrascan GitHub action. Scan infrastructure as code including Terraform, Kubernetes, Helm, and Kustomize file for security best practice…☆56Updated 5 months ago
- in-toto is a framework to secure the software supply chain.☆70Updated 4 months ago