step-security / ai-codewise
AI-Powered Code Reviews for Best Practices & Security Issues Across Languages
☆17Updated last year
Alternatives and similar repositories for ai-codewise:
Users that are interested in ai-codewise are comparing it to the libraries listed below
- Website and API for OpenSSF Scorecard☆23Updated this week
- Purpose-built security agent for hosted runners☆29Updated 5 months ago
- An SBOM query language and associated utilities☆54Updated 11 months ago
- Security-focused Chaos Experiments for DevSecOps Teams☆24Updated 2 weeks ago
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 2 years ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆31Updated last year
- A CNI plugin for Kubernetes that allows you to connect pods to a Webmesh network.☆15Updated last year
- Lambda function for verifying signed images in ECS☆33Updated 10 months ago
- Interrogate your GitHub resources with the help of the world's greatest detectives: Powerpipe + Steampipe + Sherlock.☆39Updated 2 months ago
- Sigstore user stories☆29Updated last year
- BRAVE (Bare Metal Replication And Virtualization Environment)☆38Updated 11 months ago
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆41Updated last year
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆16Updated this week
- Compare vulnerability scanners results (to make them better!)☆16Updated this week
- An example repo demonstrating keyless signing with Github Actions☆10Updated 2 years ago
- ☆13Updated this week
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆78Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆43Updated last year
- ☆56Updated 2 years ago
- Various tools, images, etc. to support the Wolfi OSS project☆19Updated last week
- Go module to generate and transform VEX documents☆37Updated this week
- ☆27Updated this week
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- ☆18Updated 7 months ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆32Updated 6 months ago
- A draft standard for communicating a cryptographic record of build inputs for software artifacts.☆23Updated 3 months ago
- Use SQL to instantly query Prometheus metrics, alerts, labels and more. Open source CLI. No DB required.☆17Updated last month
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆70Updated 4 months ago