Projects with this topic
-
DevSecOps health check for GitLab Self-Managed instances.
Updated -
Analyzer that scans for application dependencies.
Updated -
A curated kaniko for GitLab Runner. Seven signed image variants per release on UBI9, including a FIPS-strict path for GODEBUG=fips140=only environments.
Updated -
Consumer workload: a Go binary. Adoption phase report, so conformance runs advisory and merge requests stay green.
Updated -
Deterministic, format-preserving dependency remediation for GitLab CI — Maven first. A hundred eyes on your dependency graph.
Updated -
Security-hardened reusable GitHub Actions workflows for Go, Python and Docker CI/CD: lint, test, scan, build, publish, release. Plus ClawHub skill/plugin publishing, MCP registry publish, self-rendered SVG badges, Codeberg/GitLab/Gitee mirroring, and a PR gate for non-collaborators. One uses: line, no copy-paste.
Updated -
[Reference tool] Analyze SBOM dependency graph complexity to predict BuildDependencyGraphWorker performance. CycloneDX and SPDX 2.3. No compiled artifact.
Updated -
A fast, minimal viewer for SPDX SBOMs: cascading documents, compliance profiles (NTIA, BSI TR-03183), VEX overlay. Client-side, files never leave your machine.
Updated -
Gitlab CI/CD template that facilitates scan targets against security issues
Updated -
BETA: Dependency Scanning for supported projects
Updated -
CI/CD component to extract SBOMs from GitLab projects.
Updated -
VEX exporter for GitLab projects using Dependency Scanning
Updated -
Harness Software Supply Chain CI/CD components for GitLab. SBOM, SLSA, Artifact Signing, and Policy Enforcement
UpdatedUpdated -
A fast, minimal viewer for Open Component Model deliveries: CTF archives, embedded SBOMs, client-side signature verification, OCI registry browsing.
Updated -
D3FENDer is a security assessment and gap detection tool developed by Michael Favvas for his thesis titled "Development of a security assessment and gap detection system using the MITRE ATT&CK and D3FEND Frameworks". It uses a rule based system to grade an organization's defenses based on the input. It then detects possible gaps and suggests mitigations based on the MITRE ATT&CK and D3FEND Knowledge Bases. The tool can be used in SOC work flows.
Updated -
A package for installation into PHP web-projects, for reporting data to a Metaport server.
Updated -
Integrate SCANOSS Platform with Gitlab
Updated -
Kubernetes-native Helm auditor for supply chain security, aggregating SBOM, vulnerability, and provenance data.
Updated -
A package for installation into Python web-projects, for reporting data to a Metaport server.
Updated -
A package for installation into .Net projects, for reporting data to a Metaport server.
Updated