gorrion-io / production-readiness-checklist
โ22Updated 2 months ago
Related projects โ
Alternatives and complementary repositories for production-readiness-checklist
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ75Updated 2 months ago
- โ36Updated 3 years ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.โ169Updated 9 months ago
- AI featured threat modeling and security review actionโ40Updated 5 months ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.โ104Updated 9 months ago
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ33Updated last month
- Segment's Threat Modeling training for our engineersโ238Updated 3 years ago
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and gitโ79Updated last week
- โ80Updated this week
- โ61Updated last year
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflowsโ79Updated last week
- Cloud Commotion intends to cause chaos to simulate security incidentsโ138Updated 4 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accountsโ57Updated last year
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use โฆโ61Updated 5 months ago
- Gram is Klarna's own threat model diagramming toolโ280Updated 2 weeks ago
- A full insecure kubernetes application for testing security toolsโ54Updated 2 weeks ago
- Adaptive AWS Zero Trust Policy made easy: Auto-generate least-privilege policies based on user activity in real time! Accelerate the adopโฆโ73Updated 6 months ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrixโ57Updated last year
- Detect publicly accessible Lambda Function URLs in your AWS accountโ9Updated 2 years ago
- Semgrep rules corresponding to the OWASP ASVS standardโ27Updated 4 years ago
- A tool to check the security settings of Github Organizations.โ69Updated last year
- This is a companion to the Security Engineer Questionsโ200Updated 11 months ago
- https://breaches.cloudโ36Updated 3 weeks ago
- โ121Updated last year
- An implementation of infrastructure-as-code scanning using dynamic tooling.โ56Updated 2 years ago
- Convert cloudtrail data to MITRE ATT&CK Sightingsโ79Updated 2 years ago
- โ28Updated 7 months ago
- โ109Updated 3 weeks ago
- โ30Updated 2 years ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.โ35Updated 5 months ago