hupe1980 / cdk-threagile
Agile Threat Modeling as Code
☆12Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for cdk-threagile
- Generate a score for your sbom to understand if it will actually be useful.☆221Updated 3 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- A tool to create, transform and attest VEX metadata☆116Updated this week
- Enrich SBOMs with data from third party services☆113Updated last week
- An SBOM query language and associated utilities☆54Updated 9 months ago
- Publishes BOMs to Dependency-Track from GitHub Actions☆47Updated last month
- ☆38Updated this week
- Scans SBOMs for vulnerabilities with Grype☆79Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- A tool to check the security settings of Github Organizations.☆69Updated last year
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆22Updated last week
- Lambda function for verifying signed images in ECS☆33Updated 8 months ago
- Kubernetes audit logging, when you don't control the control plane☆65Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆70Updated last week
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- The security workflow engine!☆73Updated this week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆79Updated last week
- ☆30Updated 2 weeks ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆169Updated 9 months ago
- a tool to audit the istio service mesh☆173Updated 3 years ago
- Evaluate source control (GitHub) security posture☆249Updated last year
- Trivy plugin for OCI referrers☆20Updated 6 months ago
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆45Updated 7 months ago
- ☆80Updated this week
- OpenVEX Specification☆130Updated 4 months ago
- StartLeft is an automation tool for generating Threat Models written in the Open Threat Model (OTM) format from a variety of different so…☆48Updated last week
- ☆51Updated 8 months ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆136Updated this week