kubescape / sneefferLinks
Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is based on application monitoring using eBPF and Falco base libraries and writes results in Kubernetes CRDs
☆26Updated 2 years ago
Alternatives and similar repositories for sneeffer
Users that are interested in sneeffer are comparing it to the libraries listed below
Sorting:
- sigstore the hard way!☆117Updated 2 months ago
- Scans SBOMs for vulnerabilities with Grype☆85Updated this week
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated 2 years ago
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆127Updated 2 weeks ago
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆24Updated 10 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- Administrative tooling for Falco☆111Updated last week
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆63Updated 4 years ago
- ☆20Updated 4 months ago
- BadRobot - Operator Security Audit Tool☆223Updated last week
- A replacement for "kubectl exec" that works over WebSocket connections.☆41Updated last year
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- Kubernetes audit logging, when you don't control the control plane☆85Updated last week
- A place for policy work group related proposals and prototypes.☆66Updated 4 months ago
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supp…☆147Updated last week
- Runtime security plug to protect user containers☆66Updated this week
- sigstore installation walkthrough, local☆63Updated last year
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆101Updated this week
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆68Updated last week
- Response Engine for managing threats in your Kubernetes☆173Updated 3 weeks ago
- A tool to create, transform and attest VEX metadata☆160Updated this week
- Docs and Tutorials for Chainguard☆85Updated last week
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆47Updated last week
- An admission controller service and kubectl plugin to handle container drift in K8s clusters☆125Updated 3 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Generate a variety of suspect actions that are detected by Falco rulesets☆110Updated 4 months ago
- ☆74Updated 5 months ago
- ☆35Updated 3 years ago
- Anchore Kubernetes Inventory can poll Kubernetes Cluster API(s) to tell Anchore Enterprise which Containers and Images are currently in-u…☆67Updated last week