Projects with this topic
-
A curated kaniko for GitLab Runner. Signed and attested container builds: six image variants per release on UBI9, standard and FIPS 140-3, with CycloneDX SBOM and SLSA provenance.
Updated -
DevSecOps health check for GitLab Self-Managed instances.
Updated -
Chapter 4: a Go binary at report phase. Gaps are published and advisory, so the merge request stays green while the finding rides along.
Updated -
Analyzer that scans for application dependencies.
Updated -
[Reference tool] Analyze SBOM dependency graph complexity to predict BuildDependencyGraphWorker performance. CycloneDX and SPDX 2.3. No compiled artifact.
Updated -
Security-hardened reusable GitHub Actions workflows for Go, Python and Docker CI/CD: lint, test, scan, build, publish, release. Plus ClawHub skill/plugin publishing, MCP registry publish, self-rendered SVG badges, Codeberg/GitLab/Gitee mirroring, and a PR gate for non-collaborators. One uses: line, no copy-paste.
Updated -
BETA: Dependency Scanning for supported projects
Updated -
-
A package for installation into .Net projects, for reporting data to a Metaport server.
Updated -
A package for installation into PHP web-projects, for reporting data to a Metaport server.
Updated -
A package for installation into Python web-projects, for reporting data to a Metaport server.
Updated -
A package for installation into NodeJS web-projects, for reporting data to a Metaport server.
Updated -
A fast, minimal viewer for SPDX SBOMs: cascading documents, compliance profiles (NTIA, BSI TR-03183), VEX overlay. Client-side, files never leave your machine.
Updated -
Gitlab CI/CD template that facilitates scan targets against security issues
Updated -
CI/CD component to extract SBOMs from GitLab projects.
Updated -
VEX exporter for GitLab projects using Dependency Scanning
Updated -
Harness Software Supply Chain CI/CD components for GitLab. SBOM, SLSA, Artifact Signing, and Policy Enforcement
UpdatedUpdated -
A fast, minimal viewer for Open Component Model deliveries: CTF archives, embedded SBOMs, client-side signature verification, OCI registry browsing.
Updated -
D3FENDer is a security assessment and gap detection tool developed by Michael Favvas for his thesis titled "Development of a security assessment and gap detection system using the MITRE ATT&CK and D3FEND Frameworks". It uses a rule based system to grade an organization's defenses based on the input. It then detects possible gaps and suggests mitigations based on the MITRE ATT&CK and D3FEND Knowledge Bases. The tool can be used in SOC work flows.
Updated -
Integrate SCANOSS Platform with Gitlab
Updated