communitysec / sbom-hall-of-fameLinks
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆43Updated 2 years ago
Alternatives and similar repositories for sbom-hall-of-fame
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
Sorting:
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆114Updated this week
- A tool to check the security settings of Github Organizations.☆72Updated 2 years ago
- ☆114Updated 3 months ago
- Supply-Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆206Updated last week
- Useful scripts, Docker images, docker-compose apps, and Terraform modules.☆151Updated last week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- Compares and analyzes GCP IAM roles.☆77Updated 9 months ago
- AWS honey token manager☆89Updated last year
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆103Updated last year
- An SBOM query language and associated utilities☆54Updated last year
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆46Updated last week
- Documenting your Threat Models with HCL☆438Updated 3 weeks ago
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆60Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated 2 years ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆106Updated last week
- A Golang program to rotate AWS & GCP account keys☆65Updated 6 months ago
- kntrl is an eBPF based runtime agent that monitors and prevents anomalous behaviour defined by you on your pipeline. kntrl achieves this …☆123Updated 2 months ago
- Automated testing, generation & manipulation of #osquery packs☆73Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆177Updated last year
- Generate a score for your sbom to understand if it will actually be useful.☆234Updated last year
- (D)ocker(F)ile (C)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆94Updated 2 months ago
- 💅🏽 analyzes your github actions☆97Updated 2 months ago
- ☆74Updated last month
- This Terraform module consists of the configuration for automating the remediation of AWS EC2 vulnerabilities using AWS Inspector finding…☆50Updated 5 months ago
- ## Auto-archived due to inactivity. ## Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Securit…☆37Updated last year
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆40Updated last year
- Security Alert Decoration☆27Updated 4 months ago
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- The security workflow engine!☆135Updated 3 weeks ago