sethvargo / ratchet
A tool for securing CI/CD workflows with version pinning.
☆804Updated this week
Alternatives and similar repositories for ratchet:
Users that are interested in ratchet are comparing it to the libraries listed below
- Keyless Git signing using Sigstore☆974Updated this week
- git-xargs is a command-line tool (CLI) for making updates across multiple Github repositories with a single command.☆985Updated last week
- Build OCI images from APK packages directly without Dockerfile☆1,294Updated last week
- Open source compliance tool for development platforms.☆286Updated last year
- Public Chainguard Images☆584Updated this week
- Evaluate source control (GitHub) security posture☆249Updated 2 years ago
- tfquery: Run SQL queries on your Terraform infrastructure. Query resources and analyze its configuration using a SQL-powered framework.☆322Updated 2 years ago
- GitHub App to set and enforce security policies☆1,292Updated last week
- Vulnerability scanning just got lazier☆286Updated last week
- Publish from GitHub Actions using multi-factor authentication☆284Updated this week
- Cloud native secrets management for developers - never leave your command line for secrets.☆2,978Updated 7 months ago
- A Declarative Dependency Management tool☆652Updated this week
- An anonymous & ephemeral Docker image registry☆584Updated 5 months ago
- Automated changelog tool for preparing releases with lots of customization options☆739Updated this week
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆745Updated last week
- Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes se…☆963Updated 6 months ago
- An open source command line interface that runs checks on infrastructure as code to catch potential deployment issues before deploying.☆471Updated last year
- Valet helps facilitate the migration of Azure DevOps, CircleCI, GitLab CI, Jenkins, and Travis CI pipelines to GitHub Actions.☆508Updated last year
- /ˈheɪvənə/ - Think of it as a swiss army knife for Kubernetes tasks☆329Updated this week
- Regal is a linter and language server for Rego, bringing your policy development experience to the next level!☆287Updated last week
- Anchore container analysis and scan provided as a GitHub Action☆233Updated this week
- An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchm…☆742Updated 3 months ago
- Main package repository for production Wolfi images☆905Updated this week
- ☆682Updated this week
- Convert Kubernetes YAML to Golang☆1,259Updated last year
- A tool to sync images from one container registry to another☆620Updated 9 months ago
- Update multiple repositories in with one command☆966Updated 2 weeks ago
- Write tests against structured configuration data using the Open Policy Agent Rego query language☆2,933Updated this week
- Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities☆902Updated last week
- A security layer for Git repositories☆498Updated this week