philips-labs / continuous-compliance-actionLinks
Continuous Compliance makes it possible to enforce company policy on repositories. Continuous Compliance will automatically check your repository for mandatory files or requirements. When possible, it will create detailed Github issue with instructions on how to resolve it.
☆22Updated 2 months ago
Alternatives and similar repositories for continuous-compliance-action
Users that are interested in continuous-compliance-action are comparing it to the libraries listed below
Sorting:
- GitHub Advance Security Compliance Action☆134Updated 3 years ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆33Updated 3 years ago
- Github Action implementation of SLSA Provenance Generation☆50Updated this week
- Sets up Open Policy Agent CLI in your GitHub Actions workflow.☆55Updated 2 weeks ago
- ☆83Updated last year
- ☆51Updated last month
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆79Updated last week
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆136Updated this week
- GitHub Advanced Security Policy as Code☆94Updated last month
- Generate SBOMs with gh CLI☆197Updated 8 months ago
- GitHub Secret Scanning Auto Remediator (GSSAR)☆46Updated last month
- An SBOM query language and associated utilities☆55Updated 2 years ago
- Example of using Actions OIDC token to proxy into a private network☆105Updated 10 months ago
- Need to centrally manage and run Actions workflows across multiple repositories? This app does it for you.☆135Updated last year
- Orchestrate GitHub Actions Security☆304Updated 2 weeks ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆96Updated 2 months ago
- An Action to wrap creating an SBOM via REST API☆20Updated last month
- Enrich SBOMs with data from third party services☆214Updated this week
- A tool to create, transform and attest VEX metadata☆172Updated this week
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 3 years ago
- ☆58Updated 3 years ago
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆18Updated this week
- A GitHub action for organizations that enables advanced security code scanning on all new repos☆42Updated last month
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆106Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆42Updated last week
- ☆74Updated last month
- Website and API for OpenSSF Scorecard☆28Updated last week
- An OIDC client to retrieve a GitHub API scoped token from within an Actions workflow☆33Updated last year
- Go library for Sigstore signing and verification☆18Updated 2 years ago
- A GitHub action to measure GitHub Actions workflow metrics. An enabler to put the concept discussed in the post to practice - https://www…☆23Updated 2 years ago