sethvargo / ratchet
A tool for securing CI/CD workflows with version pinning.
☆828Updated last week
Alternatives and similar repositories for ratchet:
Users that are interested in ratchet are comparing it to the libraries listed below
- Keyless Git signing using Sigstore☆993Updated this week
- Open source compliance tool for development platforms.☆286Updated last year
- git-xargs is a command-line tool (CLI) for making updates across multiple Github repositories with a single command.☆995Updated 3 weeks ago
- Update multiple repositories in with one command☆1,008Updated last week
- Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes se…☆966Updated 8 months ago
- Tool and policy library for reviewing Google Kubernetes Engine clusters against best practices☆524Updated 3 weeks ago
- Build OCI images from APK packages directly without Dockerfile☆1,342Updated this week
- GitHub App to set and enforce security policies☆1,302Updated this week
- A security layer for Git repositories☆514Updated this week
- Terratag is a CLI tool that enables users of Terraform to automatically create and maintain tags across their entire set of AWS, Azure, a…☆976Updated 2 weeks ago
- Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, an…☆818Updated this week
- Detect, track and alert on infrastructure drift☆2,533Updated last month
- Evaluate source control (GitHub) security posture☆249Updated 2 years ago
- A GitHub App that enforces approval policies on pull requests☆832Updated this week
- tfquery: Run SQL queries on your Terraform infrastructure. Query resources and analyze its configuration using a SQL-powered framework.☆325Updated 2 years ago
- An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchm…☆746Updated 4 months ago
- Public Chainguard Images☆595Updated this week
- A Declarative Dependency Management tool☆719Updated this week
- Orchestrate GitHub Actions Security☆284Updated 2 weeks ago
- Regal is a linter and language server for Rego, bringing your policy development experience to the next level!☆297Updated this week
- An anonymous & ephemeral Docker image registry☆595Updated 6 months ago
- Verify provenance from SLSA compliant builders☆257Updated 3 weeks ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆472Updated this week
- Automatically removes Cloud managed services and Kubernetes resources based on tags with TTL☆222Updated last week
- Anchore container analysis and scan provided as a GitHub Action☆241Updated this week
- Vulnerability scanning just got lazier☆288Updated 3 weeks ago
- A Terraform / OpenTofu state migration tool for GitOps☆1,199Updated last week
- Pike is a tool for determining the permissions or policy required for IAC code☆707Updated this week
- Write tests against structured configuration data using the Open Policy Agent Rego query language☆2,966Updated this week
- /ˈheɪvənə/ - Think of it as a swiss army knife for Kubernetes tasks☆329Updated this week