vendorsec / mvsp
Minimum Viable Secure Product mvsp.dev
☆191Updated 3 months ago
Alternatives and similar repositories for mvsp:
Users that are interested in mvsp are comparing it to the libraries listed below
- Security policies for Tailscale☆287Updated 3 months ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆171Updated 4 months ago
- An open-source collection of API key rotation tutorials.☆70Updated 3 weeks ago
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 7 months ago
- ☆100Updated 2 weeks ago
- App that simplifies building decision trees to model adverse scenarios☆207Updated 9 months ago
- OpenVEX Specification☆144Updated 2 weeks ago
- ☆165Updated 7 months ago
- boostsecurityio/poutine☆263Updated last week
- A tool to check the security settings of Github Organizations.☆71Updated last year
- ☆208Updated 6 months ago
- An Open Letter to the OWASP Board☆106Updated last year
- Vendor Security Model Contract☆98Updated 2 years ago
- ☆112Updated 3 months ago
- Core model including reused documentation☆95Updated 2 weeks ago
- ☆60Updated 2 months ago
- Segment's Threat Modeling training for our engineers☆243Updated 3 years ago
- A Software as a Service (SaaS) log collection framework.☆163Updated 3 weeks ago
- ☆97Updated 2 weeks ago
- Threatest is a CLI and Go framework for end-to-end testing threat detection rules.☆329Updated last year
- Open Source Software Secure Supply Chain Framework☆236Updated 2 years ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆120Updated 2 months ago
- Enrich SBOMs with data from third party services☆165Updated last week
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆107Updated last year
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆92Updated last week
- Mirror of cisa.gov/kev data files☆45Updated this week
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year
- This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.☆137Updated 2 years ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated last year
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆148Updated 4 months ago