kubescape / sneefferLinks
Sneefer is a PoC project showing how to filter out irrelevent vulnerabilities from container image vulnerability scan results. It is based on application monitoring using eBPF and Falco base libraries and writes results in Kubernetes CRDs
☆26Updated last year
Alternatives and similar repositories for sneeffer
Users that are interested in sneeffer are comparing it to the libraries listed below
Sorting:
- Scans SBOMs for vulnerabilities with Grype☆84Updated last week
- The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.☆125Updated last week
- sigstore the hard way!☆115Updated this week
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated last year
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated 2 years ago
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated 7 months ago
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- Kubernetes audit logging, when you don't control the control plane☆84Updated this week
- BadRobot - Operator Security Audit Tool☆221Updated 3 weeks ago
- Trust Dexter to ensure that all your images are pinned by digest for better security☆30Updated last year
- Runtime security plug to protect user containers☆66Updated this week
- A replacement for "kubectl exec" that works over WebSocket connections.☆40Updated last year
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆62Updated 4 years ago
- A tool to create, transform and attest VEX metadata☆151Updated this week
- a tool to audit the istio service mesh☆173Updated 3 years ago
- A kubectl plugin to visualize network policies rules.☆96Updated last year
- This repository contains the code used during my demo at BSidesNYC 2023 where I presented a new method for analysing volatile memory in G…☆1Updated 9 months ago
- ☆56Updated 3 weeks ago
- (D)ocker(F)ile (C)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆82Updated 2 weeks ago
- ☆21Updated 2 months ago
- Generate a variety of suspect actions that are detected by Falco rulesets☆106Updated 2 months ago
- Security advisory data for Wolfi☆19Updated this week
- Administrative tooling for Falco☆110Updated last week
- ☆20Updated 2 months ago
- A place for policy work group related proposals and prototypes.☆67Updated 2 months ago
- ☆20Updated 2 months ago
- Response Engine for managing threats in your Kubernetes☆168Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- sigstore installation walkthrough, local☆62Updated last year
- kubectl plugin for signing Kubernetes manifest YAML files with sigstore☆84Updated 3 weeks ago