Stars
The GitHub Action for Microsoft Application Inspector
Python tool for converting files and office documents to Markdown.
This is a step-by-step guide to implementing a DevSecOps program for any size organization
Language-agnostic SLSA provenance generation for Github Actions
GitHub token permissions Monitor and Advisor actions
A GitHub Security Lab initiative, providing an in-repo learning experience, where learners secure intentionally vulnerable code.
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
Vulnerable app with examples showing how to not use secrets
Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki
tools for sandboxing your dependency graph
🐶 A curated list of Web Security materials and resources.
Semgrep rules corresponding to the OWASP ASVS standard
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon
Node.js Ecosystem Security Working Group
A public version of Unity's internal SSDLC. Meant to provide an example framework, not just to share with others, but to also take contributions and continue to improve and evolve.
Principles to help you design and deploy a zero trust architecture
Hands on labs and code to help you learn, measure, and build using architectural best practices.
Awesome Node.js Security resources
A collection of browser-based side channel attack vectors.
Automatically exported from code.google.com/p/domxsswiki
The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
threatspec - continuous threat modeling, through code
A Continuous Threat Modeling methodology
secureCodeBox (SCB) - continuous secure delivery out of the box