Projects with this topic
-
Analyzer that scans for application dependencies.
Updated -
Integrate SCANOSS Platform with Gitlab
Updated -
D3FENDer is a security assessment and gap detection tool developed by Michael Favvas for his thesis titled "Development of a security assessment and gap detection system using the MITRE ATT&CK and D3FEND Frameworks". It uses a rule based system to grade an organization's defenses based on the input. It then detects possible gaps and suggests mitigations based on the MITRE ATT&CK and D3FEND Knowledge Bases. The tool can be used in SOC work flows.
Updated -
Gitlab CI/CD template that facilitates scan targets against security issues
Updated -
Kubernetes-native Helm auditor for supply chain security, aggregating SBOM, vulnerability, and provenance data.
Updated -
DevSecOps health check for GitLab Self-Managed instances.
Updated -
BETA: Dependency Scanning for supported projects
Updated -
[Reference tool] Analyze SBOM dependency graph complexity to predict BuildDependencyGraphWorker performance. CycloneDX and SPDX 2.3. No compiled artifact.
Updated -
A package for installation into Python web-projects, for reporting data to a Metaport server.
Updated -
A package for installation into PHP web-projects, for reporting data to a Metaport server.
Updated -
A package for installation into .Net projects, for reporting data to a Metaport server.
Updated -
A fully automated 13-stage DevSecOps CI/CD pipeline that integrates security, compliance, and cloud-native deployment using GitLab CI and Amazon EKS.
The pipeline demonstrates real-world DevSecOps practices including:
• SAST, dependency, container, IaC, and Kubernetes manifest scanning • SBOM generation (CycloneDX) • Automated POA&M creation mapped to NIST controls • Evidence packaging for compliance audits • Secure image push to Amazon ECR • Deployment and validation on Amazon EKS • Full run-to-completion behavior (lab mode) with findings documented rather than blocking
This project showcases an end-to-end secure software supply chain workflow suitable for: cloud engineering, DevOps, cybersecurity, and compliance automation demonstrations.
Updated -
A package for installation into NodeJS web-projects, for reporting data to a Metaport server.
Updated -
VEX exporter for GitLab projects using Dependency Scanning
Updated -
CI/CD component to extract SBOMs from GitLab projects.
Updated -
-
metaeffekt / metaeffekt-automation
CI/CD Catalog (unpublished)This project illustrates the use of metaeffekt Kontinuum within Gitlab.
Updated