octo-sts / app
A GitHub App that acts like a Security Token Service (STS) for the Github API
☆171Updated this week
Alternatives and similar repositories for app:
Users that are interested in app are comparing it to the libraries listed below
- ☆40Updated 4 months ago
- CLI to prevent malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions…☆85Updated this week
- A collection of reusable Github Actions workflows.☆128Updated this week
- Github Action to automatically update digests for container images.☆54Updated last week
- Throw a tag at it and it comes back with a checksum.☆114Updated this week
- Evaluate source control (GitHub) security posture☆249Updated 2 years ago
- Dynamic GitHub Actions from Wolfi packages☆43Updated 10 months ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆80Updated this week
- An SBOM query language and associated utilities☆54Updated last year
- A tool to create, transform and attest VEX metadata☆132Updated this week
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆48Updated 11 months ago
- ☆56Updated 2 years ago
- Verify provenance from SLSA compliant builders☆250Updated 3 weeks ago
- ☆53Updated this week
- Create and store a hash of the Terraform modules used by your configuration☆76Updated 8 months ago
- Add comments to pull requests where tfsec checks have failed☆167Updated last year
- Kubernetes audit logging, when you don't control the control plane☆71Updated this week
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Inspect certificate authorities in container images☆230Updated this week
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year
- Protect GitHub Actions with Tracee☆80Updated last month
- Format agnostic SBOM tooling☆102Updated this week
- A Golang program to rotate AWS & GCP account keys☆65Updated last week
- Pre-commit git hooks for Open Policy Agent (OPA) and Rego development☆66Updated 3 years ago
- [Experimental] jail for Go modules☆75Updated this week
- Run tfsec with reviewdog on pull requests to enforce security best practices☆74Updated last week
- GitHub Action for creating software bill of materials using Syft.☆176Updated this week
- Experimental: TFLint ruleset plugin for writing custom rules in Rego.☆67Updated last week
- A flexible Terraform provider for making API calls☆137Updated last week