hupe1980 / cdk-threagileLinks
Agile Threat Modeling as Code
☆13Updated 3 years ago
Alternatives and similar repositories for cdk-threagile
Users that are interested in cdk-threagile are comparing it to the libraries listed below
Sorting:
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- Generate a score for your sbom to understand if it will actually be useful.☆231Updated last year
- Evaluate source control (GitHub) security posture☆252Updated 2 years ago
- Scans SBOMs for vulnerabilities with Grype☆84Updated last week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- BadRobot - Operator Security Audit Tool☆221Updated 3 weeks ago
- Enrich SBOMs with data from third party services☆183Updated last week
- Pre-commit git hooks for Open Policy Agent (OPA) and Rego development☆66Updated last month
- A tool to create, transform and attest VEX metadata☆151Updated this week
- ☆243Updated this week
- The security workflow engine!☆118Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆97Updated this week
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆51Updated last year
- Catalogue all images of a Kubernetes cluster to multiple targets with Syft☆203Updated this week
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆174Updated 8 months ago
- sbomqs: The Comprehensive SBOM Quality & Compliance Tool☆221Updated this week
- Github action to run dependency check☆82Updated 2 months ago
- Security configuration checks for popular cloud native applications and infrastructure.☆119Updated 3 years ago
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆94Updated this week
- Kubernetes audit logging, when you don't control the control plane☆84Updated this week
- A Github Action to automatically update digests for container images.☆69Updated 3 months ago
- The Amazon Elastic Kubernetes Service (EKS) Creation Engine (ECE) is a Python command-line program created by the Lightspin Office of the…☆40Updated 2 years ago
- SCP management tool☆131Updated last year
- A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.☆194Updated last year
- Useful scripts, Docker images, docker-compose apps, and Terraform modules.☆150Updated 2 weeks ago
- Documenting your Threat Models with HCL☆432Updated 2 months ago
- Publishes BOMs to Dependency-Track from GitHub Actions☆55Updated 10 months ago
- Examples of using Snyk's SBOM APIs.☆16Updated 2 years ago
- A tool for preventing the installation of malicious npm and PyPI packages☆155Updated this week
- ☆119Updated 2 months ago