stacklok / trusty-actionLinks
Trusty Dependency Risk Action
☆10Updated 11 months ago
Alternatives and similar repositories for trusty-action
Users that are interested in trusty-action are comparing it to the libraries listed below
Sorting:
- Format agnostic SBOM tooling☆131Updated 2 months ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆97Updated last week
- Software Supply Chain Security Platform☆373Updated this week
- A repository containing example Minder rules and profiles☆24Updated last week
- Scan GitHub Actions Workflow logs for IOCs☆16Updated last week
- Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security☆141Updated last month
- Supporting code and demos for KubeCon EU 2023 talk "Malicious Compliance: Reflections on Trusting Container Image Scanners"☆67Updated 2 years ago
- 🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)☆37Updated last week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆139Updated 2 years ago
- A tool to create, transform and attest VEX metadata☆172Updated this week
- kntrl is an eBPF based runtime agent that monitors and prevents anomalous behaviour defined by you on your pipeline. kntrl achieves this …☆125Updated 4 months ago
- SBOM Move - Automate build and transfer of SBOMs across systems☆25Updated 2 weeks ago
- A MCP server that provides web content fetching capabilities.☆20Updated this week
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆514Updated this week
- ☆22Updated 6 months ago
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆10Updated 8 months ago
- Runtime Security Solution for your CI/CD Pipeline☆112Updated last week
- ☆74Updated last month
- sbomify is a product security artifact hub and a trust center.☆43Updated last week
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆111Updated last year
- ☆140Updated last week
- An MCP server for OSV☆26Updated 2 weeks ago
- (D)ocker(F)ile (C)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆98Updated last month
- Generate a score for your sbom to understand if it will actually be useful.☆237Updated last year
- MKP is a Model Context Protocol (MCP) server for Kubernetes☆56Updated this week
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆103Updated last year
- A reading list for software supply-chain security.☆366Updated 3 years ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆141Updated 11 months ago
- Validate the isolation posture of your container environment.☆310Updated last month
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆449Updated this week