Hacker News
- Trivy: A scanner for vulnerabilities in containers, file systems, and Git repos https://github.com/aquasecurity/trivy 6 comments
- A simple security scanner for vulnerabilities and configuration issues in IaC such as Kubernetes, Dockerfile and Terraform https://github.com/aquasecurity/trivy 6 comments netsec
- Tools to scan running images for vulnerabilities https://github.com/aquasecurity/trivy 29 comments kubernetes
Linking pages
- GitHub - trimstray/the-book-of-secret-knowledge: A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. https://github.com/trimstray/the-book-of-secret-knowledge 278 comments
- GitHub - analysis-tools-dev/static-analysis: ⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality. https://github.com/analysis-tools-dev/static-analysis 112 comments
- AWS Publishes Reference Architecture and Implementations for Deployment Pipelines https://www.infoq.com/news/2023/02/aws-deployment-pipelines/ 51 comments
- GitHub - rust-secure-code/cargo-auditable: Make production Rust binaries auditable https://github.com/Shnatsel/rust-audit 45 comments
- GitHub - whalehub/ginstall.sh: A shell script that can install the compiled binaries of CLI tools straight from their GitHub release page. https://github.com/whalehub/ginstall.sh 45 comments
- Which Container Images To Use — Distroless Or Alpine? | by Tanmay Deshpande | ITNEXT https://deshpandetanmay.medium.com/which-container-images-to-use-distroless-or-alpine-96e3dab43a22?sk=7a9f3ce6627c810e5138cdc59b9dbbcd 38 comments
- GitHub - komodorio/validkube: ValidKube combines the best open-source tools to help ensure Kubernetes YAML best practices, hygiene & security. https://github.com/komodorio/validkube 28 comments
- GitHub - rust-secure-code/cargo-auditable: Make production Rust binaries auditable https://github.com/rust-secure-code/cargo-auditable 25 comments
- GitHub - ChristofferNissen/helmper: Import Helm Charts to OCI registries, optionally with vulnerability patching https://github.com/ChristofferNissen/helmper 22 comments
- GitHub - analysis-tools-dev/static-analysis: ⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality. https://github.com/mre/awesome-static-analysis#c 21 comments
- GitHub - komodorio/helm-dashboard: The missing UI for Helm - visualize your releases https://github.com/komodorio/helm-dashboard 21 comments
- Docker optimization guide: the 12 best tips to optimize Docker image security https://www.augmentedmind.de/2022/02/20/optimize-docker-image-security/ 15 comments
- Web Application Security Checklist – AppSec Monkey https://www.appsecmonkey.com/blog/web-application-security-checklist/ 11 comments
- GitHub - ml-tooling/ml-workspace: 🛠 All-in-one web-based IDE specialized for machine learning and data science. https://github.com/ml-tooling/ml-workspace 10 comments
- GitHub - trimstray/the-book-of-secret-knowledge: A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. https://github.com/trimstray/awesome-ninja-admins 10 comments
- GitHub - sottlmarek/DevSecOps: Ultimate DevSecOps library https://github.com/sottlmarek/DevSecOps 8 comments
- Introducing a community-driven advisory database for third-party software dependencies | GitLab https://about.gitlab.com/blog/2022/02/16/a-community-driven-advisory-database/ 6 comments
- Creating Safer Containerized PHP Runtimes with Wolfi - DEV Community https://dev.to/erikaheidi/creating-safer-containerized-php-runtime-environments-with-wolfi-1ioa 6 comments
- Terraform Development Pipeline https://mycloudrevolution.com/2024/05/23/terraform-development-pipeline/ 6 comments
- GitHub - antonbabenko/pre-commit-terraform: pre-commit git hooks to take care of Terraform configurations 🇺🇦 https://github.com/antonbabenko/pre-commit-terraform?tab=readme-ov-file#terraform_providers_lock 6 comments
Linked pages
Would you like to stay up to date with DevOps? Checkout DevOps
Weekly.