mchmarny / s3cmeLinks
Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
☆103Updated last year
Alternatives and similar repositories for s3cme
Users that are interested in s3cme are comparing it to the libraries listed below
Sorting:
- ☆57Updated this week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆114Updated last week
- prel(iminary) is an application that temporarily assigns Google Cloud IAM Roles and includes an approval process.☆45Updated this week
- An SBOM query language and associated utilities☆55Updated 2 years ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆111Updated last year
- Kubernetes audit logging, when you don't control the control plane☆90Updated last week
- kntrl is an eBPF based runtime agent that monitors and prevents anomalous behaviour defined by you on your pipeline. kntrl achieves this …☆125Updated 4 months ago
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆60Updated 3 weeks ago
- a tool to audit the istio service mesh☆174Updated 4 years ago
- ☆115Updated 5 months ago
- ☆86Updated 3 weeks ago
- ☆76Updated 3 months ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- Runtime Security Solution for your CI/CD Pipeline☆111Updated last week
- A tool to create, transform and attest VEX metadata☆172Updated this week
- Runtime security plug to protect user containers☆67Updated this week
- ☆28Updated 8 months ago
- Scans SBOMs for vulnerabilities with Grype☆85Updated this week
- The security workflow engine!☆136Updated 2 months ago
- BadRobot - Operator Security Audit Tool☆223Updated last month
- A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of mater…☆43Updated 2 years ago
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆40Updated last year
- ☆73Updated 8 months ago
- K8s API Honeypot with Active Defense Capabilities☆44Updated 2 years ago
- Trust Dexter to ensure that all your images are pinned by digest for better security☆31Updated 2 years ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated 2 years ago
- CLI to prevent malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions…☆88Updated last week
- SBOM Move - Automate build and transfer of SBOMs across systems☆25Updated last week
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated 2 years ago