sig-security
badPods
Our great sponsors
sig-security | badPods | |
---|---|---|
20 | 2 | |
1,929 | 529 | |
2.0% | 4.0% | |
9.8 | 1.8 | |
1 day ago | almost 2 years ago | |
HTML | Shell | |
GNU General Public License v3.0 or later | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
sig-security
-
Cloud Native Applications - Part 2: Security
Cloud Native Security Whitepaper
-
Secure software supply chain: why every link matters
Fortunately, not every attack has a big enough impact to appear in the newspaper, but let’s analyze some of the most relevant and recent ones. Many other examples of different types of supply chain attacks are also collected by the CNCF in their Catalog of Supply Chain Compromises.
-
Transparency and user agency as principles for distributing and consuming open source software packages
Hooks, triggers and other artifacts are regularly abused to achieve certain automation goals such as preseeding configuration or performing certain provisioning steps right after install, sometimes overreaching in terms of administrative privileges usage with broad security implications.
badPods
We haven't tracked posts mentioning badPods yet.
Tracking mentions began in Dec 2020.
What are some alternatives?
cool-system - The Cloud Optimized Operational Lab (COOL) system
mkosi - 💽 Build Bespoke OS Images
slsa - Supply-chain Levels for Software Artifacts
spack - A flexible package manager that supports multiple versions, configurations, platforms, and compilers.
cyclonedx-gomod - Creates CycloneDX Software Bill of Materials (SBOM) from Go modules
ostree - Operating system and container binary deployment and upgrades
sample-tf-opa-policies
prowler - Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more
vscode-datree - Simple VSCode Extension that allows you to run Datree tests on Kubernetes configurations.
podschecker - podschecker is a simple script thats check your pods health on your terminal, it can send x11 notifications
Ansible - Ansible is a radically simple IT automation platform that makes your applications and systems easier to deploy and maintain. Automate everything from code deployment to network configuration to cloud management, in a language that approaches plain English, using SSH, with no agents to install on remote systems. https://docs.ansible.com.
ESPKey - Wiegand data logger, replay device and micro door-controller