endorlabs / sbom-lab
Evaluate and compare SBOMs of Maven projects
☆11Updated last year
Related projects ⓘ
Alternatives and complementary repositories for sbom-lab
- Highly automated, up-to-date, and well-documented repository template. Checks for common problems, Markdown, YAML, Bash, formats, lints, …☆11Updated 10 months ago
- Security-focused Chaos Experiments for DevSecOps Teams☆23Updated 4 months ago
- OSCAL SSP content for technologies shipped by Red Hat☆15Updated last year
- Custom semgrep rules registry☆12Updated 2 years ago
- Report missing advisories and corrections on OSS Index☆17Updated last year
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- DefectDojo Community Content☆17Updated last month
- Decision trees generated via Graphviz to inform pragmatic threat modelling.☆10Updated 3 years ago
- Collection of dynamic security related helpers☆15Updated last year
- An auto-scoring capture-the-flag game focusing on TOCTOU vulnerabilities☆18Updated 4 years ago
- The official Prelude-Correlator GitHub mirror of https://www.prelude-siem.org/projects/prelude-correlator/repository☆10Updated 3 years ago
- The Auditree tool for adding external evidence.☆10Updated last month
- OpenSSF Project Template☆17Updated 11 months ago
- ZAP Management Scripts☆21Updated this week
- Automated process to build and distribute Posture & Exposure Reports' bi-weekly to customers.☆17Updated 8 months ago
- experimental threat modeling tools☆14Updated 2 years ago
- OWASP Threat Dragon with Gitlab Integration☆24Updated 7 years ago
- Policy Pipeline : place an SDLC around your compliance documentation with a pipeline that renders policy-as-code to human friendly format…☆11Updated 4 years ago
- Deceptive tradecraft should be fun and light, not stern and stressful. It is cool to be cute.☆13Updated 11 months ago
- FSL Test bench - Ansible playbook repository to setup a save environment for security auditing and testing. It can be used for teaching s…☆28Updated 4 months ago
- The Auditree data gathering and reporting tool.☆13Updated 2 months ago
- Register your Kubernetes IPs to monitor.shodan.io☆18Updated 2 years ago
- ☆14Updated 3 months ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- A dashboard framework for visualizing complex data sets on T1V multi-panel displays☆19Updated last year
- Dependency vulnerability auditor for Ruby☆14Updated 2 months ago
- Sample code snippets for consuming the CloudSploit API☆13Updated last year
- Checks whether a Windows server according to security best practices as defined in the CIS Distribution-Independent Windows Benchmark☆16Updated 5 months ago
- Go wrapper for awslabs/certlint☆24Updated 4 years ago