woodruffw / gha-hazmatLinks
A menagerie of insecure and exploitable GitHub Actions workflows and action definitions
☆16Updated 3 months ago
Alternatives and similar repositories for gha-hazmat
Users that are interested in gha-hazmat are comparing it to the libraries listed below
Sorting:
- Throw a tag at it and it comes back with a checksum.☆153Updated this week
- Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded☆79Updated last week
- 💅🏽 analyzes your github actions☆97Updated 3 weeks ago
- List of known AWS accounts☆250Updated last month
- boostsecurityio/poutine☆356Updated this week
- Darkfiles finds orphaned files in container images and makes them to bad deeds☆42Updated 2 years ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆114Updated last week
- A GitHub Action to suggest removal of non-organization members from CODEOWNERS files☆136Updated this week
- CLI to prevent malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions…☆88Updated last week
- yams is a Go library, server, and CLI providing foundational capabilities to simulate access for AWS IAM policies☆35Updated last week
- Scans your Github Actions for security issues☆88Updated last month
- An SBOM query language and associated utilities☆55Updated 2 years ago
- Baseline rules files to improve the security of AI-generated code (Claude, Cursor, Copilot + more)☆211Updated last month
- (D)ocker(F)ile (C)onverter: CLI to convert Dockerfiles to use Chainguard Images and APKs in FROM and RUN lines etc.☆97Updated 3 weeks ago
- A place for the InfoSec community to share and celebrate real stories of organizations successfully using SBOMs (and other bills of mater…☆43Updated 2 years ago
- An open-source collection of API key rotation tutorials.☆76Updated 4 months ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆301Updated this week
- Enrich SBOMs with data from third party services☆213Updated last month
- A tool to check the security settings of Github Organizations.☆75Updated 2 years ago
- GitGoat is an open source tool that was built to enable DevOps and Engineering teams to design and implement a sustainable misconfigurati…☆171Updated last year
- Evaluate source control (GitHub) security posture☆251Updated 2 years ago
- An IAM Simulator that outputs detailed explains of how a request was evaluated.☆97Updated last week
- Documenting your Threat Models with HCL☆453Updated last month
- AWS honey token manager☆89Updated last year
- a fast changelog generator sourced from PRs and Issues☆60Updated this week
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated 2 years ago
- ☆51Updated last month
- The Evidence Store for Your Entire Supply Chain. SBOMs, xBOMs and every other artifact - stored for 10+ years, versioned and audit-ready.☆87Updated this week
- Interrogate your GitHub resources with the help of the world's greatest detectives: Powerpipe + Steampipe + Sherlock.☆41Updated 5 months ago
- A Terraform module that makes it a snap to opt out of all AWS AI/ML data harvesting.☆30Updated 2 years ago