crashappsec / chalk
Chalk allows you to follow code from development, through builds and into production.
☆368Updated this week
Alternatives and similar repositories for chalk:
Users that are interested in chalk are comparing it to the libraries listed below
- boostsecurityio/poutine☆261Updated 3 weeks ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆148Updated 4 months ago
- CI/CD Security Analyzer☆655Updated last month
- Use AI to Scan Your Code from the Command Line for security and code smells. Bring your own keys. Supports OpenAI and Gemini☆161Updated last year
- A tool to check the security settings of Github Organizations.☆71Updated last year
- A security layer for Git repositories☆502Updated this week
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆170Updated 4 months ago
- A multi-vault secret injection tool for safely injecting secrets into app environment☆121Updated last week
- A universal SBOM representation in protocol buffers☆280Updated last week
- Open-source best practices for protecting a secure, sensible cloud platform☆124Updated 5 months ago
- Gram is Klarna's own threat model diagramming tool☆319Updated 2 weeks ago
- A list of cloud security tools and vendors.☆155Updated 6 months ago
- Documenting your Threat Models with HCL☆425Updated 6 months ago
- Software Supply Chain Security Platform☆325Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆431Updated this week
- Generate a score for your sbom to understand if it will actually be useful.☆227Updated 7 months ago
- A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs☆382Updated this week
- Evaluate source control (GitHub) security posture☆249Updated 2 years ago
- A tool for preventing the installation of malicious PyPI and npm packages☆130Updated this week
- ☆217Updated 3 months ago
- Validate the isolation posture of your container environment.☆256Updated last week
- Open source compliance tool for development platforms.☆286Updated last year
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆273Updated 6 months ago
- Powerpipe: Dashboards for DevOps. Visualize cloud configurations. Assess security posture against a massive library of benchmarks. Build …☆367Updated this week
- Automate permissions to your cloud and critical applications.☆239Updated last year
- Minimum Viable Secure Product mvsp.dev☆191Updated 3 months ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated 11 months ago
- Evidence store for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more☆394Updated this week
- AWS honey token manager☆87Updated 7 months ago
- select * from logs; Tailpipe is an open source SIEM for instant log insights, powered by DuckDB. Analyze millions of events in seconds, r…☆391Updated this week