kubescape / sneefferLinks
Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is based on application monitoring using eBPF and Falco base libraries and writes results in Kubernetes CRDs
☆26Updated 2 years ago
Alternatives and similar repositories for sneeffer
Users that are interested in sneeffer are comparing it to the libraries listed below
Sorting:
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated 2 years ago
- Scans SBOMs for vulnerabilities with Grype☆85Updated this week
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆25Updated 11 months ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆103Updated last year
- sigstore the hard way!☆116Updated 3 months ago
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆128Updated 2 weeks ago
- A replacement for "kubectl exec" that works over WebSocket connections.☆42Updated last year
- Kubernetes audit logging, when you don't control the control plane☆88Updated this week
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆63Updated 4 years ago
- BadRobot - Operator Security Audit Tool☆223Updated this week
- Runtime security plug to protect user containers☆66Updated last week
- ☆20Updated 5 months ago
- Trust Dexter to ensure that all your images are pinned by digest for better security☆31Updated 2 years ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆103Updated last week
- Administrative tooling for Falco☆114Updated last week
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- A tool to create, transform and attest VEX metadata☆166Updated last week
- ☆20Updated 5 months ago
- Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supp…☆149Updated this week
- A place for policy work group related proposals and prototypes.☆65Updated 6 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Response Engine for managing threats in your Kubernetes☆183Updated last week
- ☆74Updated 6 months ago
- a tool to audit the istio service mesh☆173Updated 4 years ago
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆68Updated this week
- OWASP Kubernetes security and compliance tool [WIP]☆107Updated 2 years ago
- KBOM - Kubernetes Bill of Materials☆323Updated 3 months ago
- sigstore installation walkthrough, local☆62Updated last year
- ☆35Updated 4 years ago