Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai
This project is a collection of automated hardening frameworks and Ansible roles designed to secure Linux systems, databases, SSH services, and web servers. It functions as a configuration framework that reduces the attack surface of Linux distributions through the automated enforcement of security policies. The collection provides specific security baselines for a variety of services, including MySQL databases, OpenSSH daemons, and web servers such as Nginx and Apache. These roles are designed to remove insecure defaults, enforce secure authentication methods, and align system configurations
The open-source policy-as-code software that provides analysis for Multi-Cloud and SaaS environments, you can get insight with natural language (powered by OpenAI).
preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.
A CVE scanner which can process a pkglist.
Principalele funcționalități ale baalmor/cve-ape sunt: DevOps Security.
Alternativele open-source pentru baalmor/cve-ape includ: aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… dev-sec/ansible-os-hardening — This project is a collection of automated hardening frameworks and Ansible roles designed to secure Linux systems,… selefra/selefra — The open-source policy-as-code software that provides analysis for Multi-Cloud and SaaS environments, you can get… spectralops/preflight — preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack. spectralops/teller — Cloud native secrets management for developers - never leave your command line for secrets.