cybrota / scharfLinks
Static analysis tool to Identify and Fix GitHub Actions prone to Supply‑Chain Risks
☆14Updated last month
Alternatives and similar repositories for scharf
Users that are interested in scharf are comparing it to the libraries listed below
Sorting:
- Enrich SBOMs with data from third party services☆214Updated this week
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆10Updated 8 months ago
- Scan GitHub Actions Workflow logs for IOCs☆16Updated this week
- ☆76Updated 3 months ago
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆60Updated last month
- Format agnostic SBOM tooling☆131Updated 2 months ago
- The security workflow engine!☆136Updated 2 months ago
- Generate a score for your sbom to understand if it will actually be useful.☆237Updated last year
- SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It suppor…☆217Updated this week
- Machine-readable specification for the attestation of security-relevant data.☆72Updated last week
- OpenVEX Specification☆166Updated 3 weeks ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆114Updated this week
- Sharing software supply chain security open source projects☆53Updated 3 years ago
- Utility that provides an API platform for validating, querying and managing BOM data☆124Updated last month
- A standard API specification for exchanging supply chain artifacts and intelligence☆98Updated 2 weeks ago
- Supply-Chain Firewall (SCFW) is a tool for preventing the installation of malicious npm and PyPI packages☆215Updated this week
- Add a layer of active defense to your cloud applications.☆103Updated this week
- SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context P…☆137Updated 8 months ago
- sbomasm: The Complete SBOM Management Toolkit☆101Updated last week
- ☆93Updated 3 months ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆103Updated last year
- A Software as a Service (SaaS) log collection framework.☆182Updated 3 weeks ago
- An IAM Simulator that outputs detailed explains of how a request was evaluated.☆97Updated last week
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆267Updated this week
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated 2 years ago
- Automating Compliance Tooling Project☆22Updated 4 years ago
- A universal SBOM representation in protocol buffers☆315Updated last week
- ☆115Updated 5 months ago
- ☆228Updated 2 weeks ago
- 💅🏽 analyzes your github actions☆97Updated last month