oxsecurity / ox-security-scan
A GitHub Action for using OX Security to scan for vulnerabilities in your software projects
☆12Updated 2 months ago
Alternatives and similar repositories for ox-security-scan:
Users that are interested in ox-security-scan are comparing it to the libraries listed below
- Runtime Security Solution for your CI/CD Pipeline☆94Updated 4 months ago
- Compare vulnerability scanners results (to make them better!)☆16Updated 2 weeks ago
- Generate a score for your sbom to understand if it will actually be useful.☆224Updated 5 months ago
- ☆19Updated last week
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.☆35Updated 3 years ago
- Enrich SBOMs with data from third party services☆152Updated this week
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain☆90Updated last year
- The Logger that will prevent your data leak☆95Updated this week
- GitHub Advanced Security Policy as Code☆77Updated 2 weeks ago
- Tool for collecting vulnerability data from various sources (used to build the grype database)☆84Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆61Updated last year
- DefectDojo Community Content☆17Updated 3 months ago
- ☆52Updated this week
- Clean accounts over permissions in GCP infra at scale☆71Updated last year
- An SBOM query language and associated utilities☆54Updated last year
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- A tool to check the security settings of Github Organizations.☆70Updated last year
- Security-focused Chaos Experiments for DevSecOps Teams☆24Updated 3 weeks ago
- GitHub Secret Scanning Auto Remediator (GSSAR)☆44Updated last year
- Compares and analyzes GCP IAM roles.☆77Updated 8 months ago
- A tool to create, transform and attest VEX metadata☆126Updated this week
- An open-source collection of API key rotation tutorials.☆63Updated last month
- Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code securi…☆76Updated 5 months ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- NIST OSCAL SDK and CLI☆18Updated 6 months ago
- Identify all permitted data paths originating from the Internet to Network Interfaces within AWS Accounts across the entire AWS Organizat…☆36Updated last year
- a fast changelog generator sourced from PRs and Issues☆54Updated this week
- Repository for on-going work as part of the AIBOM Tiger Team effort.☆18Updated 4 months ago
- Run individual controls or full compliance benchmarks for NSA CISA Kubernetes Hardening Guidance across all of your Kubernetes clusters u…☆32Updated 3 months ago
- Format agnostic SBOM tooling☆96Updated this week