Projects with this topic
-
Analyzer that scans for application dependencies.
Updated -
DevSecOps health check for GitLab Self-Managed instances.
Updated -
A fast, minimal viewer for SPDX SBOMs: cascading documents, compliance profiles (NTIA, BSI TR-03183), VEX overlay. Client-side, files never leave your machine.
Updated -
Gitlab CI/CD template that facilitates scan targets against security issues
Updated -
CI/CD component to extract SBOMs from GitLab projects.
Updated -
VEX exporter for GitLab projects using Dependency Scanning
Updated -
D3FENDer is a security assessment and gap detection tool developed by Michael Favvas for his thesis titled "Development of a security assessment and gap detection system using the MITRE ATT&CK and D3FEND Frameworks". It uses a rule based system to grade an organization's defenses based on the input. It then detects possible gaps and suggests mitigations based on the MITRE ATT&CK and D3FEND Knowledge Bases. The tool can be used in SOC work flows.
Updated -
Kubernetes-native Helm auditor for supply chain security, aggregating SBOM, vulnerability, and provenance data.
Updated -
A fully automated 13-stage DevSecOps CI/CD pipeline that integrates security, compliance, and cloud-native deployment using GitLab CI and Amazon EKS.
The pipeline demonstrates real-world DevSecOps practices including:
• SAST, dependency, container, IaC, and Kubernetes manifest scanning • SBOM generation (CycloneDX) • Automated POA&M creation mapped to NIST controls • Evidence packaging for compliance audits • Secure image push to Amazon ECR • Deployment and validation on Amazon EKS • Full run-to-completion behavior (lab mode) with findings documented rather than blocking
This project showcases an end-to-end secure software supply chain workflow suitable for: cloud engineering, DevOps, cybersecurity, and compliance automation demonstrations.
Updated -