woodruffw / gha-hazmat
A menagerie of insecure and exploitable GitHub Actions workflows and action definitions
☆11Updated 2 weeks ago
Alternatives and similar repositories for gha-hazmat
Users that are interested in gha-hazmat are comparing it to the libraries listed below
Sorting:
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆64Updated 3 weeks ago
- a fast changelog generator sourced from PRs and Issues☆58Updated this week
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated 2 years ago
- Audit your Node version for known CVEs and patches☆25Updated this week
- Throw a tag at it and it comes back with a checksum.☆135Updated this week
- ☆16Updated 3 months ago
- Compare data from multiple vulnerability scanners to get a more complete picture of potential exposures.☆64Updated last year
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated this week
- GitHub Actions Runner images for AWS☆26Updated this week
- Use SQL to instantly query repositories, users, gists and more from GitHub. Open source CLI. No DB required.☆85Updated this week
- Always know where you need to run Terraform plan & apply!☆67Updated last year
- Use SQL to instantly query & run shell commands on local & remote servers. Open source CLI. No DB required.☆11Updated 3 weeks ago
- Terraform module for a secret with owner/writer/reader roles.☆11Updated this week
- A GitHub action to run hadolint and reports violations given a Dockerfile within a repository☆13Updated last year
- Manage a directory of binaries without a package manager☆30Updated this week
- Vim Plugin for Trivy☆14Updated last year
- Agile Threat Modeling as Code☆13Updated 2 years ago
- (d)ocker(f)ile (c)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆49Updated this week
- An SBOM query language and associated utilities☆54Updated last year
- Fetch user-data from a cloud provider, set the hostname, and write files. A very minimal alternative to cloud-init.☆48Updated last year
- A tool to check the security settings of Github Organizations.☆71Updated last year
- Compare vulnerability scanners results (to make them better!)☆16Updated 3 weeks ago
- Use SQL to instantly query data from CSV files. Open source CLI. No DB required.☆21Updated 3 weeks ago
- Dynamic GitHub Actions from Wolfi packages☆43Updated last year
- Use SQL to instantly query DNS records, certificates and other network information. Open source CLI. No DB required.☆25Updated last month
- Attaché provides an emulation layer for Cloud Provider IMDS APIs☆53Updated 10 months ago
- Firefox containers extension for Granted☆16Updated last year
- InfraSpec is a tool for running infrastructure tests written in pure Gherkin syntax☆30Updated last month
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆189Updated this week
- ☆66Updated this week