crashappsec / github-analyzer
A tool to check the security settings of Github Organizations.
☆71Updated last year
Alternatives and similar repositories for github-analyzer:
Users that are interested in github-analyzer are comparing it to the libraries listed below
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆171Updated 3 months ago
- ☆112Updated 2 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- ☆53Updated this week
- A tool for preventing the installation of malicious PyPI and npm packages☆128Updated last week
- ☆98Updated last week
- Generate a score for your sbom to understand if it will actually be useful.☆226Updated 7 months ago
- AWS honey token manager☆87Updated 7 months ago
- Enrich SBOMs with data from third party services☆161Updated last month
- OpenVEX Specification☆143Updated 8 months ago
- Compares and analyzes GCP IAM roles.☆77Updated last week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated 10 months ago
- An SBOM query language and associated utilities☆54Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis tool☆39Updated last year
- A full insecure kubernetes application for testing security tools☆70Updated this week
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- Cloud Commotion intends to cause chaos to simulate security incidents☆145Updated 9 months ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆87Updated this week
- Safer AWS SCP deployments via real-time monitoring☆50Updated last year
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 6 months ago
- A Golang program to rotate AWS & GCP account keys☆65Updated last week
- ☆47Updated last year
- This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.☆137Updated 2 years ago
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 3 years ago
- ☆163Updated 6 months ago
- The security workflow engine!☆102Updated this week
- GCP CSPM using Google Sheets☆35Updated 9 months ago