magnologan / gha-devsecops
DevSecOps Pipeline using SAST + DAST and SCA tools
☆63Updated 4 months ago
Alternatives and similar repositories for gha-devsecops:
Users that are interested in gha-devsecops are comparing it to the libraries listed below
- Sample DevSecOps pipelines (heavily biased on the "Sec") for various stacks and tools using open-source security tools and AWS native ser…☆68Updated 3 years ago
- A list of resources blogs talks material about DevSecOps☆91Updated 3 years ago
- workshop about cloud-native security☆71Updated 2 years ago
- OWASP Foundation Web Respository☆82Updated 2 months ago
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use …☆66Updated 9 months ago
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.☆98Updated last year
- Examples of integrating the Snyk CLI into a CI/CD system☆87Updated 3 months ago
- A curated list of Software Component Analysis (SCA) books, courses - free and paid, videos, tools, and tutorials.☆103Updated 4 months ago
- OWASP Foundation Web Respository☆55Updated last year
- A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.☆188Updated last year
- ☆90Updated 5 months ago
- AWS Certified Security Specialty (2020) course notes☆117Updated 4 years ago
- OWASP Kubernetes security and compliance tool [WIP]☆106Updated last year
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆107Updated last year
- Security Champions Playbook v 2.1☆360Updated last year
- ☆521Updated last week
- A collection of DoD and Federal Government Cloud Computing Resources☆48Updated 3 years ago
- A collection of diagramming tools to help create DevOps/DevSecOps reference architectures☆67Updated last year
- Create custom auto-remediation solutions using serverless functions in the cloud.☆53Updated last year
- Count distinct contributor of Snyk watched repos across several SCM☆32Updated 9 months ago
- A docker container to simplify and secure the use of Infrastructure as Code (IaC)☆71Updated this week
- GitHub action to scan container images with Palo Alto Networks' Prisma Cloud☆56Updated last week
- ☆282Updated 2 years ago
- ☆406Updated 2 years ago
- A collection of DevSecOps reference architectures☆67Updated 4 years ago
- Awesome resources about Security in Kubernetes☆42Updated 2 years ago
- OWASP Foundation Web Respository☆581Updated last year
- ThreatModel for Amazon S3 - Library of all the attack scenarios on Amazon S3, and how to mitigate them following a risk-based approach☆152Updated last year
- An AWS IAM policy statement parser and query tool.☆174Updated last year
- A deliberately vulnerable Kubernetes cluster☆124Updated last year