hupe1980 / cdk-threagile
Agile Threat Modeling as Code
☆13Updated 2 years ago
Alternatives and similar repositories for cdk-threagile:
Users that are interested in cdk-threagile are comparing it to the libraries listed below
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- An SBOM query language and associated utilities☆54Updated last year
- Enrich SBOMs with data from third party services☆158Updated last week
- A tool to check the security settings of Github Organizations.☆71Updated last year
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- Utility that provides an API and CLI to identify licenses and legal terms☆43Updated 8 months ago
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- Publishes BOMs to Dependency-Track from GitHub Actions☆50Updated 4 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated 2 months ago
- Generate a score for your sbom to understand if it will actually be useful.☆225Updated 6 months ago
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 3 years ago
- vscode extension for tfsec☆30Updated 2 years ago
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆48Updated 10 months ago
- ☆46Updated this week
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- Kubernetes audit logging, when you don't control the control plane☆67Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆33Updated this week
- Grype vulnerability check plugin for Visual Studio Code☆22Updated 2 months ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆79Updated this week
- Scans SBOMs for vulnerabilities with Grype☆79Updated this week
- Slack alert bot for matching Github Audit Events☆10Updated 3 months ago
- A tool for preventing the installation of malicious PyPI and npm packages☆124Updated this week
- Sysdig Terraform provider. Allow to handle Sysdig Secure policies as code.☆51Updated this week
- Examples of using Snyk's SBOM APIs.☆16Updated 2 years ago
- Pre-commit git hooks for Open Policy Agent (OPA) and Rego development☆66Updated 3 years ago
- Check images in your charts for vulnerabilities☆42Updated last year
- Kubernetes Admission Controller for Image Scanning using OPA☆50Updated last year
- ☆32Updated 3 months ago