mondoohq / cnspec
An open source, cloud-native security to protect everything from build to runtime
☆275Updated this week
Related projects ⓘ
Alternatives and complementary repositories for cnspec
- open source, cloud-native, graph-based asset inventory☆320Updated this week
- ☸️ Mondoo Client Kubernetes Operator☆36Updated this week
- This repository contains security policies for cnspec maintained by Mondoo and the cnspec community.☆43Updated this week
- Packer plugin cnspec by Mondoo - Build machine images free of security misconfigurations and vulnerabilities!☆27Updated this week
- Evaluate source control (GitHub) security posture☆249Updated last year
- All-in-one auditing toolkit for identifying common security issues in managed Kubernetes environments. Currently supports Amazon EKS.☆318Updated 10 months ago
- ☆228Updated this week
- Documenting your Threat Models with HCL☆401Updated 2 months ago
- BadRobot - Operator Security Audit Tool☆215Updated this week
- The Terraform Live Graph Extension for Visual Studio Code is a plugin that allows you to generate a live Terraform graph as you code.☆237Updated last year
- Open source compliance tool for development platforms.☆286Updated last year
- ☆279Updated last year
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆66Updated 11 months ago
- This repository contains query packs for cnquery maintained by Mondoo and the cnquery community.☆25Updated 2 weeks ago
- Inspect certificate authorities in container images☆228Updated 6 months ago
- Automate permissions to your cloud and critical applications.☆238Updated 9 months ago
- Catalogue all images of a Kubernetes cluster to multiple targets with Syft☆194Updated this week
- A collection of tools to improve your containerized apps security posture☆131Updated 5 months ago
- KBOM - Kubernetes Bill of Materials☆307Updated 3 weeks ago
- A list of cloud security tools and vendors.☆135Updated 2 months ago
- Get notified when actions are taken in the AWS Console.☆252Updated 2 weeks ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆139Updated this week
- Style guide for Rego☆196Updated 2 months ago
- Notice: Postee is no longer under active development or maintenance.☆211Updated last month
- A tool to detect drifts in terraform IaC☆228Updated last year
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆416Updated this week
- Ranger RPC is a simple and fast proto-based RPC framework☆15Updated this week
- CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.☆266Updated 2 months ago
- A collection of reusable Github Actions workflows.☆119Updated this week
- IAMbic is Version-Control for IAM. It centralizes and simplifies cloud access and permissions. It maintains an eventually consistent, hum…☆285Updated last week