dcodx / gitarmor
GitArmor is a handy tool that makes it easy to assess the secure setup of your DevOps platform.
☆12Updated last month
Alternatives and similar repositories for gitarmor:
Users that are interested in gitarmor are comparing it to the libraries listed below
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆507Updated this week
- GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment☆456Updated last week
- NextJS-based single-page application for completing and reviewing SAMM assessments☆70Updated last year
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆107Updated last year
- GitHub Action to generate GitHub Advanced Security (GHAS) metrics report☆18Updated 3 weeks ago
- GitHub action to scan container images with Palo Alto Networks' Prisma Cloud☆54Updated 3 weeks ago
- GitHub Advanced Security Policy as Code☆79Updated this week
- A simple threat modeling tool to help humans to reduce time-to-value when threat modeling☆514Updated last week
- boostsecurityio/poutine☆254Updated last week
- A full insecure kubernetes application for testing security tools☆66Updated this week
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆273Updated 5 months ago
- GitHub Advance Security Compliance Action☆132Updated 2 years ago
- Cloud Commotion intends to cause chaos to simulate security incidents☆143Updated 8 months ago
- OWASP Domain Protect - prevent subdomain takeover☆401Updated last month
- ☆359Updated 10 months ago
- ☆404Updated 2 years ago
- This is a companion to the Security Engineer Questions☆202Updated last year
- Terraform provider for Prisma Cloud Compute☆25Updated 3 months ago
- Examples of Custom Secret Scanning Patterns☆155Updated 7 months ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆81Updated this week
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.☆98Updated last year
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆146Updated 3 months ago
- A list of cloud security tools and vendors.☆146Updated 5 months ago
- An AWS IAM policy statement parser and query tool.☆173Updated last year
- ☆163Updated 5 months ago
- ☆82Updated 3 years ago
- An open project to list all publicly known cloud vulnerabilities and CSP security issues☆319Updated this week
- A tool for preventing the installation of malicious PyPI and npm packages☆124Updated last week
- A tool that aims to bulk automates the enablement of GitHub Code Scanning, Secret Scanning and Dependabot across multiple repositories.☆153Updated 8 months ago