Projects with this topic
-
Deterministic, format-preserving dependency remediation for GitLab CI — Maven first. A hundred eyes on your dependency graph.
Updated -
Bounded, DoS-safe regex compilation for patterns from untrusted sources. Part of the phpboyscout Go toolkit. · https://regexutil.go.phpboyscout.uk
Updated -
Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. · https://redact.go.phpboyscout.uk
Updated -
Centralized, TPM 2.0 hardware-backed cryptographic identity enclave and multi-protocol bridge for Linux (FIDO2/CTAP2 WebAuthn Passkeys, OpenSSH Agent, GnuPG LibAssuan, age-plugin, encrypted config store).
Updated -
Full set of AppArmor profiles (~ 1500 profiles) https://apparmor.pujol.io
Updated -
Read-only mirror of cicd-sensor: An open-source runtime security monitoring tool for CI/CD environments leveraging eBPF.
Updated -
Early access (beta). REACHABLE AI SAST/SCA with reachability and exploitability proof. Proposes reviewable fix MRs; you merge.
Updated -
DEPRECATED. Please see CodeClimate-based Code Quality scanning will be removed.
Updated -
Modular JOSE toolkit for Go, built on go-jose and golang-jwt/jwt for signing, verification, encryption, and public-key distribution.
Updated -
ZTTP: Zero-Trust SSH Bastion Proxy built in Golang
Updated -
Leitwacht control plane — runtime security for GitLab Runner CI/CD: policy authoring, multi-tenancy, audit, GitLab integration
Updated -
-
eBPF + nftables + DNS proxy egress enforcement for GitLab Runner CI/CD job containers — community edition data plane
Updated -
Koyane-Framework :: wordlist forge & analysis toolkit
Updated -
The modern, high-speed successor to nsec3walker. A specialized NSEC3 forensics engine built in Go for rapid zone harvesting and automated hash reversal, optimized for accuracy and multi-core performance.
Updated -
Cellar Documentation: https://cellar-app.io | API Reference https://cellar-app.gitlab.io/cellar-api
Updated -
-
Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is used to show how the GitLab vulnerability report can be populated by a custom scanner. You can see a demo of it in action be following the documentation in the Secret List project.
Updated -
Simple Arp Monitor for suspicious arp packages in the LAN
Updated -
Google Cloud Shift-left security demonstration containing infrastructure, continuous delivery pipeline and tooling to support security from within a build pipeline
Updated