testifysec / go-imaLinks
go-ima is a tool that checks if a file has been tampered with. It is useful in ensuring integrity in CI systems
☆13Updated last year
Alternatives and similar repositories for go-ima
Users that are interested in go-ima are comparing it to the libraries listed below
Sorting:
- Red team tool that emulates the SolarWinds CI compromise attack vector.☆24Updated last year
- Witness Examples☆11Updated last year
- Example project using SLSA 3 Generic Generator with GoReleaser☆10Updated last year
- vexctl is a tool to attest VEX impact statements☆44Updated 2 years ago
- An query language and interactive tooling to work with SBOM data.☆14Updated 9 months ago
- Inspect SSL/TLS traffic using eBPF☆19Updated 8 months ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆23Updated last month
- A trivial wrapper around spf13/cobra to simplify some basic patterns☆22Updated last year
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆43Updated last year
- Go beyond package manager discovery for SBOM☆18Updated 3 years ago
- Inject Falco and pdig into a running kubernetes pod☆13Updated 5 years ago
- ☆33Updated 5 months ago
- A lightweight CLI tool that finds system calls being called inside golang applications.☆31Updated 3 years ago
- ☆21Updated 2 months ago
- ☆23Updated 2 years ago
- ☆17Updated 3 years ago
- Sigstore user stories☆30Updated last year
- A Kubewarden Policy that detects usage of deprecated and dropped Kubernetes resources☆16Updated this week
- ☆20Updated last month
- A curated list of awesome CNAB (Cloud Native Applications Bundles) | https://cnab.io/☆16Updated 4 years ago
- Kubernetes security scanner based on the open-source container vulnerability scanner Trivy.☆23Updated 4 years ago
- 🔍 Rekor transparency log monitoring and alerting☆27Updated last year
- Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko gene…☆104Updated last year
- TACOS framework structural details☆20Updated 2 months ago
- replace a k8s deployment by a proxy to a pod in another cluster☆10Updated 4 years ago
- Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the …☆14Updated 2 years ago
- Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues i…☆22Updated 5 years ago
- ☆57Updated 3 years ago
- Library to work with linux namespaces in go☆34Updated last year
- A docker CLI plugin for verifying signed attestations on images☆13Updated last year