kubescape / sneeffer
Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is based on application monitoring using eBPF and Falco base libraries and writes results in Kubernetes CRDs
☆26Updated last year
Related projects ⓘ
Alternatives and complementary repositories for sneeffer
- Scans SBOMs for vulnerabilities with Grype☆79Updated last week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆73Updated this week
- Software signing just got easier☆15Updated 11 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Creates PolicyReports based on the different Trivy Operator CRDs like VulnerabilityReports☆57Updated last week
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆42Updated last month
- A CLI used to work with the Wolfi OSS project☆57Updated this week
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- A tool to create, transform and attest VEX metadata☆119Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- A replacement for "kubectl exec" that works over WebSocket connections.☆35Updated 7 months ago
- Go module to generate and transform VEX documents☆34Updated last month
- ☆24Updated 6 months ago
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆121Updated this week
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated last year
- sigstore the hard way!☆110Updated 6 months ago
- ☆35Updated 3 years ago
- This projects contains pre-made policies for Kubernetes Validating Admission Policies. This policy library is based on Kubescape controls…☆48Updated last week
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆56Updated this week
- ☆20Updated 3 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆66Updated 11 months ago
- Runtime security plug to protect user containers☆65Updated this week
- An admission controller service and kubectl plugin to handle container drift in K8s clusters☆125Updated 2 years ago
- Intent driven security automation framework☆25Updated last week
- Kubernetes audit logging, when you don't control the control plane☆65Updated this week
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆58Updated this week
- A pane of glass between you and your Kubernetes clusters.☆45Updated 10 months ago
- kubectl plugin for signing Kubernetes manifest YAML files with sigstore☆79Updated last week
- 🔍 Rekor transparency log monitoring and alerting☆27Updated last year
- Administrative tooling for Falco☆87Updated this week