philips-labs / continuous-compliance-actionLinks
Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your repository for mandatory files or requirements. When possible, it will create detailed Github issue with instructions on how to resolve it.
☆22Updated last month
Alternatives and similar repositories for continuous-compliance-action
Users that are interested in continuous-compliance-action are comparing it to the libraries listed below
Sorting:
- Github Action implementation of SLSA Provenance Generation☆50Updated last week
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆54Updated last month
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆33Updated 3 years ago
- ☆51Updated last month
- ☆83Updated last year
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆79Updated 2 weeks ago
- Website and API for OpenSSF Scorecard☆29Updated this week
- GitHub Advance Security Compliance Action☆134Updated 3 years ago
- Generate SBOMs with gh CLI☆197Updated 7 months ago
- Load used actions from an entire organization☆17Updated last week
- An Action to wrap creating an SBOM via REST API☆20Updated 3 weeks ago
- Example of using Actions OIDC token to proxy into a private network☆105Updated 9 months ago
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆135Updated last week
- A simple tool for converting Rego (OPA) rule into command.☆31Updated 3 years ago
- CodeQL Extractor, Library, and Queries for Infrastructure as Code☆57Updated 2 weeks ago
- SLSA level 3 action☆11Updated last year
- An SBOM query language and associated utilities☆55Updated last year
- GitHub Advanced Security Policy as Code☆91Updated 3 weeks ago
- ⚡️Snyk API powered import tool to help you automate & monitor a large scale import into Snyk organizations. Designed for onboarding with …☆42Updated last week
- Synchronize GitHub Code Scanning alerts to Jira issues☆95Updated last month
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆103Updated last week
- Unified Policy Engine☆69Updated 4 months ago
- GitHub Secret Scanning Auto Remediator (GSSAR)☆46Updated last week
- Go library for Sigstore signing and verification☆18Updated 2 years ago
- ☆58Updated 3 years ago
- A tool to create, transform and attest VEX metadata☆170Updated 2 weeks ago
- Helm Chart for deploying GUAC☆18Updated 7 months ago
- GitHub Actions Importer helps you plan and automate the migration of Azure DevOps, Bamboo, CircleCI, GitLab, Jenkins, and Travis CI pipel…☆60Updated last year
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 3 years ago
- A Terraform module to manage GitHub Teams. https://github.com/☆54Updated last year