communitysec / sbom-hall-of-fameLinks
A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of material) to actually manage and reduce security risk in meaningful ways
☆43Updated last year
Alternatives and similar repositories for sbom-hall-of-fame
Users that are interested in sbom-hall-of-fame are comparing it to the libraries listed below
Sorting:
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated 3 weeks ago
- A tool for preventing the installation of malicious npm and PyPI packages☆160Updated this week
- Compares and analyzes GCP IAM roles.☆77Updated 6 months ago
- Useful scripts, Docker images, docker-compose apps, and Terraform modules.☆151Updated this week
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆32Updated 11 months ago
- ☆114Updated last month
- AWS honey token manager☆87Updated last year
- A tool to check the security settings of Github Organizations.☆72Updated 2 years ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- (D)ocker(F)ile (C)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆89Updated 3 weeks ago
- A Golang program to rotate AWS & GCP account keys☆65Updated 4 months ago
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆59Updated last year
- Scan GitHub Actions Workflow logs for IOCs☆15Updated last week
- ☆14Updated 3 years ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated 2 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆40Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated last year
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆176Updated 9 months ago
- An SBOM query language and associated utilities☆54Updated last year
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆102Updated this week
- This Terraform module consists of the configuration for automating the remediation of AWS EC2 vulnerabilities using AWS Inspector finding…☆49Updated 2 months ago
- Automated testing, generation & manipulation of #osquery packs☆73Updated 11 months ago
- ☆31Updated 10 months ago
- The security workflow engine!☆119Updated last week
- Runtime Security Solution for your CI/CD Pipeline☆109Updated 3 months ago
- kntrl is an eBPF based runtime agent that monitors and prevents anomalous behaviour defined by you on your pipeline. kntrl achieves this …☆118Updated 4 months ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated 2 years ago
- Security Alert Decoration☆27Updated last month
- 💅🏽 analyzes your github actions☆93Updated 3 weeks ago