slsa-framework / governanceLinks
SLSA implementation of Community Specification governance
☆18Updated last month
Alternatives and similar repositories for governance
Users that are interested in governance are comparing it to the libraries listed below
Sorting:
- Utility for bulk image, license, package, and vulnerability discovery in containerize workloads on GCP. Includes CLI and Service with cus…☆14Updated last year
- Manage a uniform team of security managers for every organization in your enterprise☆17Updated 9 months ago
- Website and API for OpenSSF Scorecard☆25Updated 3 weeks ago
- ☆112Updated last week
- Compares and analyzes GCP IAM roles.☆77Updated 2 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- ☆54Updated this week
- Terraform to run Scoutsuite security scan of projects within a Google Cloud Org. Report will be published to a GCS bucket.☆17Updated last year
- Decision trees generated via Graphviz to inform pragmatic threat modelling.☆11Updated 4 years ago
- Scan GitHub Actions Workflow logs for IOCs☆15Updated this week
- Generate SBOMs with gh CLI☆185Updated last week
- General sigstore community repo☆41Updated this week
- Supply Chain Integrity Model☆105Updated last year
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 4 months ago
- https://breaches.cloud☆39Updated 7 months ago
- A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of mater…☆42Updated last year
- ☆16Updated last year
- ☆20Updated 2 years ago
- A CLI that scans for sensitive data in source code☆14Updated 2 years ago
- ☆16Updated 10 months ago
- Exploit Prediction Scoring System (EPSS)☆26Updated 3 years ago
- An SBOM query language and associated utilities☆54Updated last year
- ☆29Updated this week
- ☆22Updated 2 years ago
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆31Updated 7 months ago
- Technical Advisory Council☆124Updated last week
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- Knowledge Report Alert & Normalization Generator☆27Updated last year
- A specification for signing methods and formats used by Secure Systems Lab projects.☆78Updated 8 months ago
- Git action to generate security lint report for Kubernetes workload YAML files on PR☆28Updated 3 years ago