snyk / snyk-docker-pluginLinks
This plugin provides dependency metadata for Docker images
☆36Updated this week
Alternatives and similar repositories for snyk-docker-plugin
Users that are interested in snyk-docker-plugin are comparing it to the libraries listed below
Sorting:
- A broker system between a public service and a private service☆111Updated last week
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆96Updated last year
- A build toolchain for Snyk Docker images.☆65Updated last week
- Simple command-line client to the Anchore Engine service☆114Updated last year
- This repository contains a sample script which can be used to enable security vulnerability alerts in all of the repositories in a given …☆80Updated last year
- Static analysis for CloudFormation templates to identify common misconfiguration☆56Updated 3 years ago
- Sysdig Terraform provider. Allow to handle Sysdig Secure policies as code.☆54Updated 2 weeks ago
- Github Action implementation of SLSA Provenance Generation☆50Updated 2 weeks ago
- Test and monitor your projects for vulnerabilities with Jenkins. This plugin is officially maintained by Snyk.☆62Updated last month
- Proof-of-concept SLSA provenance generator for GitHub Actions☆100Updated 2 years ago
- Source for official CVE Program policy documents.☆16Updated last week
- Contains scripts for running anchore engine in CI pipelines☆34Updated 3 years ago
- Github Action for integrating Security Alerts with JIRA☆54Updated last week
- ☆51Updated 8 months ago
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆17Updated last week
- A Dockerfile that creates an image with known vulnerabilities.☆50Updated 3 years ago
- 🦅 Run a StackHawk scan in GitHub Actions☆26Updated 3 months ago
- GKE CIS 1.1.0 Benchmark InSpec Profile☆27Updated 4 years ago
- Check images in your charts for vulnerabilities☆42Updated 3 months ago
- ahab is a tool to check for vulnerabilities in your apt, apk, or yum powered operating systems, powered by Sonatype OSS Index.☆68Updated last year
- Securing Alice's, Bob's and Carl's software supply chain using in-toto☆97Updated last week
- Enables scanning of docker builds in CircleCi for OS package vulnerabilities.☆13Updated 5 years ago
- Prevent leaks with gitleaks, and use tests to validate☆32Updated 4 months ago
- Docker Scan is a Command Line Interface to run vulnerability detection on your Dockerfiles and Docker images☆183Updated 2 years ago
- A GitHub action to help you scan your docker image for vulnerabilities☆222Updated 2 years ago
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆75Updated this week
- vscode extension for tfsec☆30Updated 2 years ago
- Grype vulnerability check plugin for Visual Studio Code☆23Updated 9 months ago
- Git action to generate security lint report for Kubernetes workload YAML files on PR☆28Updated 3 years ago
- ☆107Updated 2 years ago