Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance
☆103Apr 23, 2024Updated 2 years ago
Alternatives and similar repositories for s3cme
Users that are interested in s3cme are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆20Apr 30, 2026Updated last week
- How small can a Java application container image be☆21Feb 17, 2023Updated 3 years ago
- A tool to audit Erlang & Elixir dependencies, to make sure your ✨ gleam projects really sparkle!☆24Apr 26, 2026Updated last week
- sigstore installation walkthrough, local☆63Dec 8, 2025Updated 4 months ago
- A Golang program to rotate AWS & GCP account keys☆67May 12, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Utility for bulk image, license, package, and vulnerability discovery in containerize workloads on GCP. Includes CLI and Service with cus…☆13Feb 15, 2024Updated 2 years ago
- ☆26Aug 31, 2023Updated 2 years ago
- Throw a tag at it and it comes back with a checksum.☆175Updated this week
- Google Container Analysis data import utility, supports OSS vulnerability scanner reports, SLSA provenance and sigstore attestations.☆12Dec 5, 2025Updated 5 months ago
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆63Aug 4, 2021Updated 4 years ago
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆30Dec 17, 2024Updated last year
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Apr 14, 2026Updated 3 weeks ago
- A library for representing OCI image layers in an abstract filesystem☆27Jul 9, 2020Updated 5 years ago
- #supply #chain #attack #detection☆653Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Go library for acquiring a forward-looking lock in Google Cloud Storage.☆15Mar 13, 2025Updated last year
- Format agnostic SBOM tooling☆137Nov 20, 2025Updated 5 months ago
- ☆29Aug 9, 2024Updated last year
- Terraform provider to perform OCI image operations☆14Updated this week
- BadRobot - Operator Security Audit Tool☆228Feb 2, 2026Updated 3 months ago
- ☆11Nov 10, 2025Updated 5 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆42Dec 12, 2024Updated last year
- 📦 Produce secure packages and containers with declarative configurations☆300Apr 30, 2026Updated last week
- Surgically remove layers from a Docker image (with a chainsaw)☆24Oct 9, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Witness Examples☆12Feb 27, 2024Updated 2 years ago
- Template to bootstrap a fully functional, multi-region, REST service on GCP with a developer release pipeline.☆18Jun 1, 2023Updated 2 years ago
- sigstore the hard way!☆118Aug 6, 2025Updated 9 months ago
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for pre…☆51Nov 16, 2024Updated last year
- sigstore helm-charts and build scripts opinionated for running on OCP and RHEL☆12Mar 3, 2025Updated last year
- ☆11Nov 11, 2022Updated 3 years ago
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆73Apr 30, 2026Updated last week
- Compares and analyzes GCP IAM roles.☆79Mar 9, 2025Updated last year
- ☆40Aug 2, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆23Feb 20, 2023Updated 3 years ago
- A single repo that shows terraform, terragrunt, helm & docker☆21Jun 8, 2022Updated 3 years ago
- ☆87Mar 30, 2026Updated last month
- ☆19Apr 28, 2021Updated 5 years ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆347Updated this week
- ☆76Oct 18, 2025Updated 6 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆143Jan 2, 2025Updated last year