Stars
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
Open Source Cloud Native Application Protection Platform (CNAPP)
Open Source Vulnerability Management Platform
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
🛡️ Open-source and next-generation Web Application Firewall (WAF)
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Github action that publishes the JaCoCo report as a comment in the Pull Request
Push SpotBugs results as check run annotations
This Action allows you to create Docker images and push into a ECR repository.
🚀 Creates a release based on Conventional Commits
GitHub Actions for executing remote ssh commands.
This repository contains the notes and code snippets of the CKA 2024 YouTube Playlist. The content is based on the latest 2024 curriculum and includes hands-on demos, assignments, and exam-based sc…
Start your Google Cloud Journey with 150 practical demos. Google Cloud Associate Cloud Engineer certification - GCP ACE
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
GitHub Action that creates, updates, deletes and applies CloudFormation change sets
Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.
A Trivy plugin that scans and outputs the results to a html file.
Generates analysis reports from SonarQube web API.
ravipramoth / devsecops-jenkins-k8s-tf-sast-sca-dast-sonarcloud-snyk-zap-e2e-repo
Forked from asecurityguru/devsecops-jenkins-k8s-tf-sast-sca-dast-sonarcloud-snyk-zap-e2e-repoThe OSTE meta scanner is a comprehensive web vulnerability scanner that combines multiple DAST scanners, including Nikto Scanner, ZAP, Nuclei, SkipFish, and Wapiti.
A GitHub Action for running the ZAP Full scan
Github Action for automatic semantic versioning based on Conventional Commits
"Snyk IaC Security Checks" is a reusable workflow for scanning Infrastructure as Code (IaC) files. It identifies security vulnerabilities, provides a detailed report, and can update pull requests w…