vendorsec / mvsp
Minimum Viable Secure Product mvsp.dev
☆192Updated 4 months ago
Alternatives and similar repositories for mvsp:
Users that are interested in mvsp are comparing it to the libraries listed below
- Security policies for Tailscale☆290Updated last week
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆172Updated 5 months ago
- boostsecurityio/poutine☆267Updated this week
- App that simplifies building decision trees to model adverse scenarios☆208Updated 9 months ago
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Open Source Software Secure Supply Chain Framework☆236Updated 2 years ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆120Updated 3 months ago
- A tool for preventing the installation of malicious PyPI and npm packages☆140Updated this week
- Vendor Security Model Contract☆98Updated 2 years ago
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 8 months ago
- Segment's Threat Modeling training for our engineers☆243Updated 4 years ago
- ☆112Updated 3 months ago
- Documenting your Threat Models with HCL☆426Updated 8 months ago
- This repo is a consolidation of Secure Software Supply Chain resources, such as talks, whitepapers, conferences and more.☆138Updated 2 years ago
- A Software as a Service (SaaS) log collection framework.☆167Updated last week
- OpenVEX Specification☆148Updated last month
- Threatest is a CLI and Go framework for end-to-end testing threat detection rules.☆329Updated last week
- Enriching the NVD CVSS scores to include Temporal & Threat Metrics☆194Updated this week
- ☆102Updated last week
- An open-source collection of API key rotation tutorials.☆71Updated last month
- A set of policies, standards and control procedures with mapping to HIPAA, NIST CSF, PCI DSS, SOC2, FedRAMP, CIS Controls, and more.☆313Updated 10 months ago
- GitHub App to watch for PRs merged without a reviewer approving.☆124Updated 2 weeks ago
- Enrich SBOMs with data from third party services☆171Updated last month
- Core model including reused documentation☆96Updated last month
- ☆54Updated this week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆95Updated 3 weeks ago
- Evaluate source control (GitHub) security posture☆249Updated 2 years ago
- Compares and analyzes GCP IAM roles.☆77Updated last month
- An Open Letter to the OWASP Board☆106Updated last year
- The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed co…☆222Updated last year