sysdiglabs / scan-action
Inline Image Scan Github Action
☆30Updated last month
Alternatives and similar repositories for scan-action:
Users that are interested in scan-action are comparing it to the libraries listed below
- Kubernetes Admission Controller for Image Scanning using OPA☆50Updated last year
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆23Updated this week
- ☆32Updated 5 years ago
- Sigstore user stories☆29Updated last year
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆60Updated this week
- Falco Rules helpers for VSCode☆12Updated last year
- ☆19Updated 2 years ago
- ☆35Updated 3 years ago
- Service implementation for a Kubernetes Dynamic Webhook controller for interacting with Anchore☆64Updated this week
- Go implementation for CNAB content trust verification using TUF, Notary, and in-toto☆31Updated last year
- An SBOM query language and associated utilities☆54Updated last year
- Collection of kbrew recipes☆10Updated 2 years ago
- vscode extension for tfsec☆30Updated 2 years ago
- cloud native software supply chain ☁️🔗☆63Updated 4 years ago
- ☆20Updated 7 months ago
- Slack alert bot for matching Github Audit Events☆10Updated 4 months ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- Github Action implementation of SLSA Provenance Generation☆47Updated this week
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆23Updated 2 months ago
- An application that regularly scans all containers in a Kubernetes cluster for vulnerabilities☆50Updated last year
- The aqua-operator is a group of controllers that runs within a Kubernetes or Openshift cluster that provides a means to deploy and manage…☆36Updated 3 weeks ago
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆62Updated this week
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆43Updated last year
- Kubernetes Config Connector Policy Demo.☆25Updated 3 years ago
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆62Updated 3 years ago
- A GitOps workflow for multi-env deployments☆14Updated 3 years ago
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆41Updated last year
- Lint your Rego policies inside of Visual Studio Code☆15Updated 8 months ago
- Kubernetes tools in a "distroless" container☆13Updated last year
- A kubectl plugin to explore ingresses -> services -> workloads☆16Updated 4 years ago