kubescape / sneeffer
Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is based on application monitoring using eBPF and Falco base libraries and writes results in Kubernetes CRDs
☆26Updated last year
Alternatives and similar repositories for sneeffer:
Users that are interested in sneeffer are comparing it to the libraries listed below
- Scans SBOMs for vulnerabilities with Grype☆79Updated this week
- ☆25Updated 9 months ago
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated 2 years ago
- ☆35Updated 3 years ago
- A place for policy work group related proposals and prototypes.☆66Updated last month
- ☆20Updated 7 months ago
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆123Updated 2 weeks ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Anchore Kubernetes Inventory can poll Kubernetes Cluster API(s) to tell Anchore Enterprise which Containers and Images are currently in-u…☆65Updated this week
- Community curated list of System and Network policy templates for the KubeArmor and Cilium☆42Updated last month
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- kubectl plugin for signing Kubernetes manifest YAML files with sigstore☆80Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆79Updated last week
- Create Kubernetes AdmissionReview requests from Kubernetes resource manifests☆114Updated this week
- A pane of glass between you and your Kubernetes clusters.☆45Updated last year
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆62Updated 3 years ago
- a tool to audit the istio service mesh☆173Updated 3 years ago
- sigstore the hard way!☆110Updated 9 months ago
- Creates PolicyReports based on the different Trivy Operator CRDs like VulnerabilityReports☆57Updated last week
- Response Engine for managing threats in your Kubernetes☆149Updated this week
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated 2 months ago
- An admission controller service and kubectl plugin to handle container drift in K8s clusters☆124Updated 3 years ago
- sigstore installation walkthrough, local☆57Updated 10 months ago
- Kubernetes audit logging, when you don't control the control plane☆70Updated this week
- Transparenty Immutable Container Image Tags☆20Updated last year
- 🔍 Rekor transparency log monitoring and alerting☆27Updated last year
- This projects contains pre-made policies for Kubernetes Validating Admission Policies. This policy library is based on Kubescape controls…☆52Updated 3 weeks ago
- Trivy kubernetes library☆33Updated this week