selefra by selefra

The open-source policy-as-code software that provides analysis for Multi-Cloud and SaaS environments, you can get insight with natural language (powered by OpenAI).

created at March 21, 2023, 4:28 p.m.

Go

6 +0

510 +0

36 +0

GitHub
overlay by os-scar

Overlay is a browser extension helping developers evaluate open source packages before picking them

created at Jan. 29, 2023, 12:33 p.m.

JavaScript

7 +0

209 +0

17 +0

GitHub
harden-runner by step-security

Network egress filtering and runtime security for GitHub-hosted and self-hosted runners

created at Oct. 28, 2021, 4:58 p.m.

TypeScript

6 -1

533 +2

41 +0

GitHub
keyscope by SpectralOps

Keyscope is a key and secret workflow (validation, invalidation, etc.) tool built in Rust

created at Oct. 1, 2021, 12:01 p.m.

Rust

17 +0

377 +0

119 +0

GitHub
preflight by SpectralOps

preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

created at April 29, 2021, 10:37 a.m.

Go

6 +0

150 +0

45 +0

GitHub
teller by tellerops

Cloud native secrets management for developers - never leave your command line for secrets.

created at March 24, 2021, 10:49 a.m.

Rust

28 +2

2,563 +7

166 +1

GitHub
netz by SpectralOps

Discover internet-wide misconfigurations while drinking coffee

created at March 3, 2021, 6:47 p.m.

Go

14 +0

376 +1

46 +0

GitHub
fulcio by sigstore

Sigstore OIDC PKI

created at Feb. 23, 2021, 3:19 p.m.

Go

17 +0

610 +2

127 +1

GitHub
cosign by sigstore

Code signing and transparency for containers and binaries

created at Feb. 4, 2021, 12:49 p.m.

Go

51 -1

4,148 +19

497 -1

GitHub
wrongsecrets by OWASP

Vulnerable app with examples showing how to not use secrets

created at Aug. 19, 2020, 5:59 a.m.

Java

17 +0

1,160 +4

276 +2

GitHub
kics by Checkmarx

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

created at July 8, 2020, 9:46 p.m.

Open Policy Agent

25 +0

1,924 +9

286 +0

GitHub
rekor by sigstore

Software Supply Chain Transparency Log

created at June 17, 2020, 12:04 p.m.

Go

18 +0

840 +2

156 +0

GitHub
kubernetes-goat by madhuakula

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

created at June 4, 2020, 5:11 p.m.

HTML

56 +0

4,016 +13

671 +1

GitHub
cfngoat by bridgecrewio

Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

created at April 25, 2020, 12:47 a.m.

Unknown languages

10 +0

91 +1

616 +1

GitHub
terragoat by bridgecrewio

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

created at March 27, 2020, 4:56 p.m.

HCL

23 +0

1,107 +3

2,345 +6

GitHub
ThreatMapper by deepfence

Open Source Cloud Native Application Protection Platform (CNAPP)

created at Feb. 6, 2020, 10:30 a.m.

TypeScript

58 +0

4,663 +6

571 +0

GitHub
awesome-threat-modelling by hysnsec

A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.

created at Dec. 29, 2019, 6:30 a.m.

Dockerfile

64 +0

1,274 +1

233 +1

GitHub
regula by fugue

Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes security and compliance using Open Policy Agent/Rego

created at Dec. 17, 2019, 2:27 p.m.

Open Policy Agent

30 +0

936 +2

106 +0

GitHub
checkov by bridgecrewio

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

created at Nov. 27, 2019, 8:55 a.m.

Python

58 +0

6,602 +16

1,055 +2

GitHub
automatic-api-attack-tool by imperva

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

created at Nov. 6, 2019, 7:53 a.m.

Java

15 +0

438 +0

91 +0

GitHub