octo-sts / appView external linksLinks
A GitHub App that acts like a Security Token Service (STS) for the Github API
☆305Updated this week
Alternatives and similar repositories for app
Users that are interested in app are comparing it to the libraries listed below
Sorting:
- ☆53Dec 3, 2025Updated 2 months ago
- Scan GitHub Actions Workflow logs for IOCs☆16Feb 9, 2026Updated last week
- A GitHub Action used for publishing an Action to ghcr.io as an OCI container.☆114Aug 8, 2025Updated 6 months ago
- Throw a tag at it and it comes back with a checksum.☆155Updated this week
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆103Apr 23, 2024Updated last year
- Keyless Git signing using Sigstore☆1,057Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆962Feb 8, 2026Updated last week
- CLI to prevent malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions…☆88Updated this week
- Repository for the Enterprise Certificate Proxy project.☆29Updated this week
- A repository containing a collection of "glue" modules for encapsulating common Cloud Run patterns.☆28Updated this week
- Software Supply Chain Security Platform☆373Updated this week
- Semgrep-based Policy Controller for Kubernetes☆47Apr 4, 2025Updated 10 months ago
- ☆20Feb 5, 2026Updated last week
- GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment☆494Jun 27, 2025Updated 7 months ago
- A tool for securing CI/CD workflows with version pinning.☆884Jun 27, 2025Updated 7 months ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆514Updated this week
- GitHub token permissions Monitor and Advisor actions☆352Jan 31, 2026Updated 2 weeks ago
- GitHub Actions linter☆206Updated this week
- #supply #chain #attack #detection☆642Updated this week
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆60Feb 8, 2026Updated last week
- ## Auto-archived due to inactivity. ## Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Securit…☆37Oct 17, 2024Updated last year
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆63Aug 4, 2021Updated 4 years ago
- (D)ocker(F)ile (C)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆98Updated this week
- Plugin for Helm to integrate the sigstore ecosystem☆67Jan 28, 2026Updated 2 weeks ago
- Cloud Commotion intends to cause chaos to simulate security incidents☆145Jun 18, 2024Updated last year
- Language-agnostic SLSA provenance generation for Github Actions☆546Oct 20, 2025Updated 3 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆141Jan 2, 2025Updated last year
- Build OCI images from APK packages directly without Dockerfile☆1,544Updated this week
- 🍺 Alcoholless: lightweight security sandbox for Homebrew, AI agents, etc. on macOS☆134Updated this week
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes☆74Apr 14, 2025Updated 10 months ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆117Updated this week
- [Experimental] jail for Go modules☆132Updated this week
- Static analysis for GitHub Actions☆3,623Updated this week
- ☆29Aug 9, 2024Updated last year
- GitHub Action to automate versioning, releases, and documentation for Terraform modules in monorepos.☆213Feb 9, 2026Updated last week
- Software Supply Chain Transparency Log☆1,078Updated this week
- JIT Groups is an open source application that lets you implement secure, self-service access management for Google Cloud using groups.☆282Updated this week
- Expand IAM Actions with Wildcards☆34Updated this week
- Kubernetes network policies reference implementation☆69Updated this week