communitysec / sbom-hall-of-fame
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆42Updated last year
Alternatives and similar repositories for sbom-hall-of-fame:
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
- Compares and analyzes GCP IAM roles.☆77Updated 8 months ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆82Updated this week
- A tool to check the security settings of Github Organizations.☆71Updated last year
- An SBOM query language and associated utilities☆54Updated last year
- ☆53Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- ☆111Updated last month
- A tool for preventing the installation of malicious PyPI and npm packages☆124Updated this week
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆79Updated last month
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- A security tool designed to help review merged code changes to open source maintained repositories via LLM assisted review to safeguard a…☆30Updated 3 months ago
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆38Updated this week
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆30Updated 3 months ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated 9 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆39Updated last year
- GCP CSPM using Google Sheets☆34Updated 8 months ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆83Updated last week
- AWS honey token manager☆87Updated 6 months ago
- Kubernetes audit logging, when you don't control the control plane☆67Updated last week
- https://breaches.cloud☆38Updated 4 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆60Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆171Updated 2 months ago
- ☆18Updated 10 months ago
- ☆14Updated 2 years ago
- Enrich SBOMs with data from third party services☆156Updated this week
- PolicyGlass allows you to analyse one or more AWS policies' effective permissions in aggregate, by restating them in the form of PolicySh…☆59Updated 3 years ago
- ☆28Updated 3 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- A tool to create, transform and attest VEX metadata☆128Updated this week
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago