philips-labs / continuous-compliance-actionLinks
Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your repository for mandatory files or requirements. When possible, it will create detailed Github issue with instructions on how to resolve it.
☆22Updated last month
Alternatives and similar repositories for continuous-compliance-action
Users that are interested in continuous-compliance-action are comparing it to the libraries listed below
Sorting:
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆33Updated 2 years ago
- ☆46Updated 2 weeks ago
- GitHub Advance Security Compliance Action☆134Updated 2 years ago
- Github Action implementation of SLSA Provenance Generation☆50Updated last week
- Website and API for OpenSSF Scorecard☆24Updated last week
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆52Updated 2 weeks ago
- ☆81Updated last year
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆75Updated last week
- Generate SBOMs with gh CLI☆193Updated 3 months ago
- Generate a score for your sbom to understand if it will actually be useful.☆233Updated last year
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆135Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆99Updated last week
- An SBOM query language and associated utilities☆54Updated last year
- Enrich SBOMs with data from third party services☆190Updated 2 weeks ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆37Updated 4 months ago
- A tool to create, transform and attest VEX metadata☆153Updated last week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- SLSA level 3 action☆11Updated last year
- GitHub Advanced Security Policy as Code☆87Updated last week
- An Action to wrap creating an SBOM via REST API☆19Updated last week
- ☆57Updated 3 years ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆45Updated 2 years ago
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated 2 years ago
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆59Updated last year
- Example of using Actions OIDC token to proxy into a private network☆96Updated 5 months ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 7 months ago
- General sigstore community repo☆42Updated this week
- GitHub Secret Scanning Auto Remediator (GSSAR)☆46Updated last month
- Evaluate source control (GitHub) security posture☆252Updated 2 years ago