yahoo / GitHub-Security-Alerts-Workflow
Automation to Incorporate GitHub Security Alerts Into your Business Workflow
☆23Updated last year
Alternatives and similar repositories for GitHub-Security-Alerts-Workflow:
Users that are interested in GitHub-Security-Alerts-Workflow are comparing it to the libraries listed below
- Generate SBOMs with gh CLI☆180Updated 7 months ago
- ☆80Updated 11 months ago
- GitHub Advance Security Compliance Action☆133Updated 2 years ago
- GitHub Advanced Security Policy as Code☆82Updated last week
- GitHub Secret Scanning Auto Remediator (GSSAR)☆44Updated 3 weeks ago
- Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption☆88Updated 2 weeks ago
- Synchronize GitHub Code Scanning alerts to Jira issues☆85Updated 3 weeks ago
- Examples of using Snyk's SBOM APIs.☆16Updated 2 years ago
- Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the …☆181Updated last year
- GitHub Action for creating software bill of materials using Syft.☆180Updated 3 weeks ago
- Proof-of-concept SLSA provenance generator for GitHub Actions☆99Updated 2 years ago
- Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts☆34Updated 2 months ago
- Enrich SBOMs with data from third party services☆168Updated 3 weeks ago
- This repository contains a sample script which can be used to enable security vulnerability alerts in all of the repositories in a given …☆80Updated 6 months ago
- ☆62Updated 9 months ago
- Verify provenance from SLSA compliant builders☆256Updated 2 weeks ago
- Machine-readable specification for the attestation of security-relevant data.☆59Updated last week
- Guideline of best practices to follow to configure Github Enterprise Cloud in a secure way.☆37Updated 4 years ago
- Website and API for OpenSSF Scorecard☆24Updated last week
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆73Updated last year
- Search an SBOM for licenses and the packages they belong to☆84Updated last week
- A tool that aims to bulk automates the enablement of GitHub Code Scanning, Secret Scanning and Dependabot across multiple repositories.☆154Updated 10 months ago
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆96Updated last year
- Unit testing framework for test driven security of AWS, GCP, Heroku and more.☆107Updated last year
- OpenVEX Specification☆145Updated 3 weeks ago
- A GitHub action for organizations that enables advanced security code scanning on all new repos☆39Updated 3 weeks ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- ☆20Updated 3 weeks ago
- GitHub Action that provides an Organization Membership Audit☆42Updated last year
- OpenSSF Working Group on Securing Software Repositories☆103Updated last week