Projects with this topic
-
A suite of tools to assist with reviewing Open Source Software dependencies. (Mirrored from https://github.com/oss-review-toolkit/ort)
Updated -
Bedrock RMF — self-hosted NIST 800-53 Rev 5 / RMF compliance management (an eMASS / Xacta alternative): control implementations to the CCI, POA&Ms, evidence, HW/SW inventory, PPSM, STIG checklists, cloud inheritance. AGPL-3.0.
Updated -
The landing page and the ten scenarios. The thesis, the claims ledger, and the public posture mirror an assessor can check without an account.
Updated -
Chapter 6: a CI component at enforce phase. The off-catalog include is planted, and the red pipeline is the point: watch the gate stop it.
Updated -
Compliance service enforcing rules defined in the TrustFramework - Architecture Document/Compliance Document
Updated -
A Python-based CLI tool designed to scan GitLab projects for compliance against the CIS GitLab Benchmark. Check out the recommendations-as-code in this repo. Read the docs for more info.
Updated -
The conformance contract for projects under gitlab-com/public-sector.
Updated -
GitLab.com / Public Sector / STIG Analyzer
CI/CD Catalog (unpublished)AI-powered GitLab CI Component that automates DISA ASD STIG compliance analysis reducing manual checklist completion from weeks or months to minutes using GitLab Duo agentic workflows to determine compliance with the 286 security controls.
Updated -
Maintenance, asset, and configuration-change records for accredited systems. Single static binary, pure-Go SQLite, LDAP/AD auth with local break-glass accounts, hash-chained audit trail. AGPL-3.0-or-later.
Updated -
Chapter 4: a Go binary at report phase. Gaps are published and advisory, so the merge request stays green while the finding rides along.
Updated -
Chapter 3: the driver. One tool provisions the group, assesses each control, pushes verdicts, and exports OSCAL.
Updated -
Chapter 5: a container image at cutover phase. The unsigned-image gap is planted, and the red pipeline is the point: watch the floor block it.
Updated -
Source of truth for the Compliance engine, validating certificate are conforming to rules, providing shapes, schemas and trusted sources
Updated -
CLI tool for GitLab automation: sync groups to local filesystem and audit projects against security & OpenSSF best practices with automated scoring
Updated -
SharedRail is an open-source, federated payment infrastructure designed to enable secure, instant, and identity-based value transfer across currencies and borders. Built on a modular architecture with mandatory encryption, KYC, and AI-assisted human intent verification, SharedRail allows users and institutions to send and receive payments using verified email identities while maintaining full transparency, auditability, and compliance through open standards. https://roxanneardary.com/sharedrail/
Updated -
Renders the Evidence Factory group README and its ten scenarios as one site. This project holds no prose; edit gitlab-profile.
Updated -
Vibe Sec Ops: the methodology Foxx Cyber uses to ship software written with AI coding agents. Rulebook, machine-enforced gates, evidence, accepted-risk registers and POA&Ms. Not vibe coding.
Updated -
Chapter 1: the governed CI/CD Catalog and the evidence line. Published, pinned components every workload builds from.
Updated -
G.U.A.R.D. is an automated Compliance-as-Code verification tool designed for cloud-native software. It bridges the semantic gap between qualitative regulatory frameworks (such as NEN 7510 and ISO 27001) and deterministic software controls by mapping compliance requirements directly to specific code symbols (anchors) and enforcing them within CI/CD pipelines.
Updated -
Chapter 2: the policy plane. The NIST 800-53 framework, the Pipeline Execution Policy that injects the line, and the approval gates.
Updated