communitysec / sbom-hall-of-fame
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆42Updated last year
Alternatives and similar repositories for sbom-hall-of-fame
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
Sorting:
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- A tool for preventing the installation of malicious PyPI and npm packages☆143Updated last week
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- An SBOM query language and associated utilities☆54Updated last year
- ☆112Updated 4 months ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆92Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- A tool to check the security settings of Github Organizations.☆71Updated last year
- AWS honey token manager☆87Updated 9 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- ☆19Updated last month
- ☆16Updated last year
- Compares and analyzes GCP IAM roles.☆77Updated 2 months ago
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆31Updated 6 months ago
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆53Updated 10 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- Format agnostic SBOM tooling☆106Updated this week
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆94Updated last week
- ☆62Updated 9 months ago
- ☆14Updated 2 years ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆84Updated 4 months ago
- This Terraform module consists of the configuration for automating the remediation of AWS EC2 vulnerabilities using AWS Inspector finding…☆46Updated 3 months ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year
- (d)ocker(f)ile (c)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆49Updated this week
- A tool to create, transform and attest VEX metadata☆136Updated last week
- Convert cloudtrail data to MITRE ATT&CK Sightings☆80Updated 2 years ago
- Enrich SBOMs with data from third party services☆172Updated last month
- Automate vulnerability triage which prioritizes remediation over discovery☆18Updated this week