step-security / ai-codewise
AI-Powered Code Reviews for Best Practices & Security Issues Across Languages
☆19Updated last year
Alternatives and similar repositories for ai-codewise:
Users that are interested in ai-codewise are comparing it to the libraries listed below
- Website and API for OpenSSF Scorecard☆24Updated this week
- Red Teaming for AI and Cloud☆25Updated last week
- Purpose-built security agent for hosted runners☆34Updated this week
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆31Updated 2 weeks ago
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆43Updated last year
- ☆20Updated last month
- An SBOM query language and associated utilities☆54Updated last year
- ☆13Updated last month
- Lambda function for verifying signed images in ECS☆33Updated last year
- Compare vulnerability scanners results (to make them better!)☆16Updated 2 weeks ago
- Linux agent used to submit realtime SBOMs and dependency usage information to EdgeBit☆14Updated 3 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- ☆29Updated this week
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆34Updated 2 months ago
- Go implementation of The Update Framework heavily influenced by python-tuf☆13Updated last year
- ☆62Updated 9 months ago
- A specification for signing methods and formats used by Secure Systems Lab projects.☆75Updated 7 months ago
- ☆56Updated 2 years ago
- An example repo demonstrating keyless signing with Github Actions☆10Updated 2 years ago
- ☁️ 🤖 LLM agent-based simulations to generate benign and malicious Cloud logs☆12Updated 9 months ago
- Various tools, images, etc. to support the Wolfi OSS project☆21Updated this week
- Overview of philips-labs helm charts☆16Updated last week
- Agile Threat Modeling as Code☆13Updated 2 years ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- A draft standard for communicating a cryptographic record of build inputs for software artifacts.☆24Updated 3 weeks ago
- Archivista is a graph and storage service for in-toto attestations. Archivista enables the discovery and retrieval of attestations for so…☆91Updated this week
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated last year
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆16Updated last week
- Software Supply Chain Attribute Integrity (SCAI) Demos and CLI tools☆18Updated this week
- Github Action implementation of SLSA Provenance Generation☆48Updated this week