github-leak-audit
DevSecOps
github-leak-audit | DevSecOps | |
---|---|---|
1 | 5 | |
9 | 5,306 | |
- | - | |
0.0 | 4.7 | |
12 months ago | 2 months ago | |
Python | ||
GNU Affero General Public License v3.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
github-leak-audit
-
Thinking Like a Hacker: Finding Source Code Leaks on GitHub
One is an app I developed to be published alongside this blog post: https://github.com/lawndoc/github-leak-audit. The app uses GitHub’s API to monitor all your GitHub organization members’ personal public repos for potential leaks. It is specifically targeted for the accidental leak scenario described in this blog post. It will detect previously unknown code and new repos. To set it up in your organization, you’ll need to fork the repo under your organization’s ownership, set up a GitHub app or PAT secret for it, and enable the GitHub Actions workflow. Detailed instructions are in the README.
DevSecOps
- Looking for Cloud Pentesting learning.
-
Implement DevSecOps to Secure your CI/CD pipeline
Ultimate DevSecOps library
-
DevSecOps tools: what are the categories and corresponding FOSS availability?
Maybe this could give you some hints : https://github.com/sottlmarek/DevSecOps
- Devops Exercises
- DevSecOps Library
What are some alternatives?
cicd-goat - A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
awesome-incident-response - A curated list of tools for incident response
WALKOFF - A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down. #nsacyber
awesome-kubernetes-security - A curated list of awesome Kubernetes security resources
apicheck - The DevSecOps toolset for REST APIs
devops-resources - DevOps resources - Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP
goose - A robot for mapping github events into actionable HTTP payloads
awesome-azure-policy - A curated list of blogs, videos, tutorials, code, tools, scripts, and anything useful to help you learn Azure Policy - by @JesseLoudon
dockerfile-security - Static security checker for Dockerfiles
k8s-set-context - GitHub Action for setting context and retrieving Kubeconfig before deploying to Kubernetes clusters
git-alerts - Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files
Grafana-Dashboards - A variety of open-source Grafana dashboards typically for AWS and Kubernetes