communitysec / sbom-hall-of-fame
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆42Updated last year
Alternatives and similar repositories for sbom-hall-of-fame:
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- A tool for preventing the installation of malicious PyPI and npm packages☆134Updated this week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆95Updated 2 weeks ago
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- An SBOM query language and associated utilities☆54Updated last year
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- ☆112Updated 3 months ago
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆42Updated this week
- Compares and analyzes GCP IAM roles.☆77Updated last month
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- GCP CSPM using Google Sheets☆35Updated 3 weeks ago
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆229Updated 8 months ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆171Updated 5 months ago
- Enrich SBOMs with data from third party services☆168Updated 3 weeks ago
- ☆19Updated last month
- AWS honey token manager☆87Updated 8 months ago
- Automate vulnerability triage which prioritizes remediation over discovery☆16Updated this week
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆30Updated 6 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆80Updated 2 years ago
- ☆62Updated 9 months ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- A tool to create, transform and attest VEX metadata☆134Updated this week
- ☆54Updated last week
- ☆16Updated 11 months ago
- Automated testing, generation & manipulation of #osquery packs☆72Updated 6 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆40Updated last year
- A security tool designed to help review merged code changes to open source maintained repositories via LLM assisted review to safeguard a…☆30Updated 6 months ago