philips-labs / continuous-compliance-actionLinks
Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your repository for mandatory files or requirements. When possible, it will create detailed Github issue with instructions on how to resolve it.
☆22Updated last year
Alternatives and similar repositories for continuous-compliance-action
Users that are interested in continuous-compliance-action are comparing it to the libraries listed below
Sorting:
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆33Updated 2 years ago
- Github Action implementation of SLSA Provenance Generation☆49Updated last week
- GitHub Secret Scanning Auto Remediator (GSSAR)☆45Updated last month
- ☆43Updated 8 months ago
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆50Updated last year
- An SBOM query language and associated utilities☆54Updated last year
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Updated last week
- Slack alert bot for matching Github Audit Events☆10Updated 8 months ago
- Manage a uniform team of security managers for every organization in your enterprise☆18Updated 10 months ago
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆134Updated last week
- Website and API for OpenSSF Scorecard☆24Updated this week
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 5 months ago
- Go library for Sigstore signing and verification☆18Updated last year
- SLSA level 3 action☆11Updated last year
- vscode extension for tfsec☆30Updated 2 years ago
- A collection of reusable GitHub Actions for the Ministry of Justice, designed to streamline and enhance workflows across our projects. • …☆18Updated this week
- GitHub Advance Security Compliance Action☆133Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 2 years ago
- Example of using Actions OIDC token to proxy into a private network☆94Updated 3 months ago
- Terraform provider for the Codefresh API☆18Updated 2 weeks ago
- A simple tool for converting Rego (OPA) rule into command.☆29Updated 3 years ago
- 🔍 Rekor transparency log monitoring and alerting☆27Updated last year
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆69Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆43Updated last year
- An Action to wrap creating an SBOM via REST API☆18Updated this week
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Updated 2 years ago
- ☆12Updated 2 years ago
- Generate SBOMs with gh CLI☆189Updated last month
- Rego policies for enterprise-scale Compliance-as-Code with OPA Conftest.☆58Updated last year