puerco / bomshell
An query language and interactive tooling to work with SBOM data.
☆14Updated last month
Related projects ⓘ
Alternatives and complementary repositories for bomshell
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- ☆22Updated last year
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆22Updated this week
- ☆20Updated 6 months ago
- Inject Falco and pdig into a running kubernetes pod☆13Updated 4 years ago
- ☆24Updated 6 months ago
- Trust Dexter to ensure that all your images are pinned by digest for better security☆29Updated last year
- Generate K8s RBAC policies based on e2e test runs☆28Updated 3 years ago
- A replacement for "kubectl exec" that works over WebSocket connections.☆35Updated 7 months ago
- ☆19Updated 3 months ago
- This is a POC repository showing how a Kubernetes Admission Controller can be made irrelevant when verifying container image signatures☆12Updated last year
- Transparenty Immutable Container Image Tags☆20Updated last year
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆22Updated last week
- Go implementation of witness☆26Updated this week
- Tool to automate build instructions generation☆29Updated this week
- ☆29Updated 3 years ago
- Kubernetes Admission Controller for Image Scanning using OPA☆50Updated last year
- oci and apk explorer☆47Updated this week
- go-ima is a tool that checks if a file has been tampered with. It is useful in ensuring integrity in CI systems☆13Updated last year
- A CLI used to work with the Wolfi OSS project☆57Updated this week
- Integrates Spiffe and Vault to have secretless authentication☆85Updated this week
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆56Updated this week
- A curated list of awesome CNAB (Cloud Native Applications Bundles) | https://cnab.io/☆15Updated 3 years ago
- Red team tool that emulates the SolarWinds CI compromise attack vector.☆22Updated 8 months ago
- Evolution process of The Falco Project☆48Updated this week
- A Kubewarden Policy that detects usage of deprecated and dropped Kubernetes resources☆15Updated this week
- Kube State Metrics `CustomResourceState` configurations for Gateway API resources☆17Updated last week
- A repository containing Minder rules and profiles recommended by your friends at Stacklok☆17Updated this week
- Runtime security plug to protect user containers☆65Updated this week
- Open Source runtime scanner for k8s cluster and perform security audit checks based on CIS Kubernetes Benchmark specification☆65Updated 3 months ago