Skip to content

This repository contains the source for the Eclipse Foundation Security Handbook.

Notifications You must be signed in to change notification settings

eclipse-csi/security-handbook

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

Security Handbook

This repository contains the source for the Eclipse Foundation Security Handbook.

Best Practices for Securing Developers Environment

Other best practices

Tools

  • sbom-scorecard: Generate a score for your sbom to understand if it will actually be useful
  • libyear: A simple measure of software dependency freshness
  • bomber: Scans Software Bill of Materials (SBOMs) for security vulnerabilities
  • dependency-track: Continuous SBOM Analysis Platform
  • syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems
  • grype: A vulnerability scanner for container images and filesystems
  • dependency-check: OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
  • unblob: Extract files from any kind of container formats
  • hinge: Creates and updates your Dependabot config
  • tacos framework: framework for attesting to the secure software development practices of open source packages
  • trivy: Trivy is a comprehensive and versatile security scanner. Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
  • clair: Vulnerability Static Analysis for Containers
  • kube-bench: tool that checks whether Kubernetes is deployed securely by running the checks documented in the CIS Kubernetes Benchmark

Index

IT

  • Fleet: Device management

About

This repository contains the source for the Eclipse Foundation Security Handbook.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published