2 مستودعات
Security utilities designed to integrate directly into CI/CD workflows to automate vulnerability detection.
Distinguishing note: Focuses on the integration point within the development lifecycle.
Explore 2 awesome GitHub repositories matching security & cryptography · Pipeline Security Tools. Refine with filters or upvote what's useful.
Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai
Automates security checks within development pipelines to prevent vulnerable code from reaching production.
Terrascan هي أداة تحليل ثابت مصممة لتقييم ملفات تكوين البنية التحتية ككود بحثاً عن ثغرات أمنية وانتهاكات الامتثال. من خلال تحليل هذه الملفات إلى تمثيل وسيط، تحدد المخاطر قبل توفير موارد السحابة، وتعمل كمدقق امتثال للبيئات السحابية الأصلية. تعمل الأداة كمحرك سياسة ككود، مما يسمح للمستخدمين بتعريف وإنفاذ قواعد أمان مخصصة ومعايير الصناعة باستخدام لغة استعلام متخصصة. تتميز بقدرتها على التكامل مباشرة في سير عمل التطوير والنشر، مما يوفر حواجز أمان آلية يمكنها حظر عمليات النشر غير المتوافقة عبر التقارير القائمة على كود الخروج. بعيداً عن التحليل الثابت، تدعم المنصة مسح ثغرات سجل الحاويات لربط المخاطر القائمة على الصور بتكوينات البنية التحتية. كما توفر مراقبة انحراف التكوين لتتبع الموارد الموفرة مقابل خطوط أساس الأمان المعمول بها، إلى جانب آليات قمع مدفوعة بالتكوين لإدارة تجاوزات السياسة والإيجابيات الكاذبة. يوفر البرنامج كلاً من واجهة سطر أوامر للتحقق من التطوير المحلي وواجهة برمجة تطبيقات مسح يمكن الوصول إليها عبر الشبكة للتكامل عن بُعد مع أنظمة الطرف الثالث وخطوط الأنابيب الآلية.
Integrates security scanning into CI/CD workflows to automatically block non-compliant infrastructure deployments.