zaproxy / action-baseline
A GitHub Action for running the ZAP Baseline scan
☆326Updated 5 months ago
Alternatives and similar repositories for action-baseline:
Users that are interested in action-baseline are comparing it to the libraries listed below
- A GitHub Action for running the ZAP Full scan☆304Updated 5 months ago
- A set of GitHub actions for checking your projects for vulnerabilities☆550Updated 8 months ago
- A GitHub Action for running the ZAP API scan☆58Updated 5 months ago
- A GitHub action to help you scan your docker image for vulnerabilities☆221Updated 2 years ago
- ☆524Updated this week
- GitHub Advanced Security Policy as Code☆82Updated 2 weeks ago
- Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities☆945Updated last month
- GitHub Advance Security Compliance Action☆133Updated 2 years ago
- Anchore container analysis and scan provided as a GitHub Action☆241Updated this week
- ⚡️Snyk API powered import tool to help you automate & monitor a large scale import into Snyk organizations. Designed for onboarding with …☆40Updated last month
- Github action to run dependency check☆78Updated 9 months ago
- Checkmarx Scan Github Action☆29Updated 9 months ago
- Run multiple open source security static analysis tools without the added complexity with OSSAR (Open Source Static Analysis Runner).☆96Updated last year
- A Python client for the Snyk API.☆95Updated 8 months ago
- Publishes BOMs to Dependency-Track from GitHub Actions☆54Updated 7 months ago
- OWASP Foundation Web Respository☆73Updated last month
- Synchronize GitHub Code Scanning alerts to Jira issues☆85Updated last month
- Examples of Custom Secret Scanning Patterns☆159Updated 2 months ago
- Examples of integrating the Snyk CLI into a CI/CD system☆88Updated 5 months ago
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.☆100Updated last year
- 🦅 Run a StackHawk scan in GitHub Actions☆25Updated 3 weeks ago
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆839Updated last year
- ☆80Updated last year
- Checkmarx CxFlow GitHub Action with SARIF output☆53Updated this week
- A tool that aims to bulk automates the enablement of GitHub Code Scanning, Secret Scanning and Dependabot across multiple repositories.☆154Updated 10 months ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆73Updated last year
- Software Component Verification Standard (SCVS)☆144Updated last month
- Sample GitHub App which monitors and enforces rules for code scanning, Dependabot, and secret scanning alerts☆23Updated last month
- OWASP Foundation Web Respository☆63Updated last year
- creates CycloneDX Software-Bill-of-Materials (SBOM) from node-based projects☆127Updated 3 months ago