xeol-io / xeol
A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
☆361Updated this week
Alternatives and similar repositories for xeol:
Users that are interested in xeol are comparing it to the libraries listed below
- A security layer for Git repositories☆473Updated this week
- Inspect certificate authorities in container images☆229Updated 8 months ago
- Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact pro…☆423Updated this week
- Evaluate source control (GitHub) security posture☆249Updated last year
- Software Supply Chain Security Platform☆306Updated this week
- Tool to achieve policy driven vetting of open source dependencies☆247Updated this week
- Harden-Runner secures CI/CD workflows by controlling network access and monitoring activities on GitHub-hosted and self-hosted runners☆649Updated this week
- Search an SBOM for licenses and the packages they belong to☆71Updated this week
- A reading list for software supply-chain security.☆361Updated 2 years ago
- Generate a score for your sbom to understand if it will actually be useful.☆224Updated 5 months ago
- Verify provenance from SLSA compliant builders☆239Updated 2 weeks ago
- A GitHub App that acts like a Security Token Service (STS) for the Github API☆147Updated this week
- A utility to generate SPDX-compliant Bill of Materials manifests☆361Updated this week
- Kubernetes tool for scanning clusters for network policies and identifying unprotected workloads.☆414Updated this week
- Anchore container analysis and scan provided as a GitHub Action☆223Updated this week
- Powerpipe: Dashboards for DevOps. Visualize cloud configurations. Assess security posture against a massive library of benchmarks. Build …☆322Updated this week
- boostsecurityio/poutine☆243Updated last week
- Enrich SBOMs with data from third party services☆151Updated last week
- Flowpipe is a cloud scripting engine. Automation and workflow to connect your clouds to the people, systems and data that matters.☆393Updated this week
- SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It suppor…☆109Updated this week
- An open source, cloud-native security to protect everything from build to runtime☆289Updated this week
- A CLI tool to sign and verify artifacts☆374Updated this week
- BadRobot - Operator Security Audit Tool☆216Updated this week
- A tool to create, transform and attest VEX metadata☆126Updated this week
- KBOM - Kubernetes Bill of Materials☆310Updated 2 months ago
- Vulnerability scanning just got lazier☆284Updated last month
- Open source compliance tool for development platforms.☆287Updated last year
- SBOM quality score - Quality metrics for your sboms☆192Updated this week
- Catalogue all images of a Kubernetes cluster to multiple targets with Syft☆198Updated this week