cycodehq / cycode-cli
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
☆88Updated this week
Alternatives and similar repositories for cycode-cli:
Users that are interested in cycode-cli are comparing it to the libraries listed below
- Runtime Security Solution for your CI/CD Pipeline☆100Updated 2 weeks ago
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use …☆66Updated 9 months ago
- CI/CD Security Analyzer☆655Updated last month
- OWASP Foundation Web Respository☆82Updated 2 months ago
- find dangling domains in a multi cloud environment☆140Updated last week
- ☆60Updated 2 months ago
- OWASP Foundation Web Respository☆19Updated 3 weeks ago
- 🚀 Policy driven vetting of open source packages with malicious code analysis☆309Updated this week
- Publishes BOMs to Dependency-Track from GitHub Actions☆52Updated 5 months ago
- Generate a score for your sbom to understand if it will actually be useful.☆227Updated 7 months ago
- Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teams☆48Updated this week
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆170Updated 4 months ago
- boostsecurityio/poutine☆261Updated 3 weeks ago
- MetaHub is an automated contextual security findings enrichment and impact evaluation tool for vulnerability management.☆168Updated 2 weeks ago
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆132Updated last year
- A tool for preventing the installation of malicious PyPI and npm packages☆132Updated this week
- ☆48Updated 2 years ago
- A GitHub Action for running the ZAP API scan☆55Updated 4 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆61Updated 9 months ago
- A project to visualize the software supply chain☆43Updated last year
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆153Updated 7 months ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆107Updated last year
- OWASP Dependency Track API client for intergration into CI/CD pipeline☆53Updated 8 months ago
- Enrich SBOMs with data from third party services☆162Updated last month
- Vulnerable by Design AWS Cloud Development Kit (CDK) Infrastructure☆46Updated last year
- Clean accounts over permissions in GCP infra at scale☆71Updated last year
- OWASP Kubernetes security and compliance tool [WIP]☆106Updated last year
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git☆90Updated this week
- Utility that provides an API platform for validating, querying and managing BOM data☆104Updated 4 months ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆200Updated 2 months ago