woodruffw / gha-hazmatLinks
A menagerie of insecure and exploitable GitHub Actions workflows and action definitions
☆13Updated 2 weeks ago
Alternatives and similar repositories for gha-hazmat
Users that are interested in gha-hazmat are comparing it to the libraries listed below
Sorting:
- a fast changelog generator sourced from PRs and Issues☆61Updated last week
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆68Updated 3 weeks ago
- Task runner. It provides useful help messages and supports interactive prompts and validation of arguments☆41Updated this week
- GitHub Actions Runner images for AWS☆28Updated last week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆110Updated this week
- Infrastructure configuration files [maintainer=@smorimoto]☆19Updated 2 weeks ago
- A GitHub action to run hadolint and reports violations given a Dockerfile within a repository☆13Updated last year
- Audit your Node version for known CVEs and patches☆25Updated this week
- Throw a tag at it and it comes back with a checksum.☆138Updated this week
- Repository characteristics☆13Updated last week
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated 2 years ago
- Manage a directory of binaries without a package manager☆34Updated this week
- An SBOM query language and associated utilities☆54Updated last year
- Github action to retrieve all (added, copied, modified, deleted, renamed, type changed, unmerged, unknown) files and directories. Secure …☆70Updated this week
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆196Updated last week
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆134Updated this week
- Use SQL to instantly query repositories, users, gists and more from GitHub. Open source CLI. No DB required.☆85Updated this week
- Firefox containers extension for Granted☆15Updated last year
- Language Server used by IDEs as Snyk Backend for Frontends☆60Updated last week
- `gh-ph` is a GitHub CLI extension and a GitHub Action that puts commit history into your pull request description☆11Updated 10 months ago
- A tool to check the security settings of Github Organizations.☆71Updated 2 years ago
- Compare vulnerability scanners results (to make them better!)☆16Updated this week
- Manage DNS Records with Kubernetes☆64Updated 7 months ago
- CLI to prevent malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions…☆86Updated this week
- tooling to make audited kubectl exec easy☆59Updated last week
- ☆42Updated 2 years ago
- A CLI used to work with the Wolfi OSS project☆62Updated last week
- Kingfisher is a blazingly fast secret‑scanning and validation tool built in Rust☆107Updated this week
- Various tools, images, etc. to support the Wolfi OSS project☆25Updated this week
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 3 years ago