All Projects → 18F → before-you-ship

18F / before-you-ship

Licence: other
merged into the TTS Handbook

Programming Languages

ruby
36898 projects - #4 most used programming language
Dockerfile
14818 projects
SCSS
7915 projects

Projects that are alternatives of or similar to before-you-ship

Wazuh Kibana App
Wazuh - Kibana plugin
Stars: ✭ 212 (+443.59%)
Mutual labels:  compliance
steampipe-mod-kubernetes-compliance
Run individual controls or full compliance benchmarks for NSA CISA Kubernetes Hardening Guidance across all of your Kubernetes clusters using Steampipe.
Stars: ✭ 23 (-41.03%)
Mutual labels:  compliance
wazuh-packages
Wazuh - Tools for packages creation
Stars: ✭ 54 (+38.46%)
Mutual labels:  compliance
Tfsec
Security scanner for your Terraform code
Stars: ✭ 3,622 (+9187.18%)
Mutual labels:  compliance
cis benchmarks audit
Simple command line tool to check for compliance against CIS Benchmarks
Stars: ✭ 182 (+366.67%)
Mutual labels:  compliance
havengrc
☁️Haven GRC - easier governance, risk, and compliance 👨‍⚕️👮‍♀️🦸‍♀️🕵️‍♀️👩‍🔬
Stars: ✭ 83 (+112.82%)
Mutual labels:  compliance
Wazuh Docker
Wazuh - Docker containers
Stars: ✭ 213 (+446.15%)
Mutual labels:  compliance
wazuh-ansible
Wazuh - Ansible playbook
Stars: ✭ 166 (+325.64%)
Mutual labels:  compliance
lunasec
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
Stars: ✭ 1,261 (+3133.33%)
Mutual labels:  compliance
ticket-check-action
Verify that pull request titles start with a ticket ID
Stars: ✭ 29 (-25.64%)
Mutual labels:  compliance
prowler
Prowler is an Open Source Security tool for AWS, Azure and GCP to perform Cloud Security best practices assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. It contains hundreds of controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks.
Stars: ✭ 8,046 (+20530.77%)
Mutual labels:  compliance
dep-scan
Fully open-source security audit for project dependencies based on known vulnerabilities and advisories. Supports both local repos and container images. Integrates with various CI environments such as Azure Pipelines, CircleCI and Google CloudBuild. No server required!
Stars: ✭ 346 (+787.18%)
Mutual labels:  compliance
LOCKLEVEL
A prototype that demonstrates a method for scoring how well Windows systems have implemented some of the top 10 Information Assurance mitigation strategies. #nsacyber
Stars: ✭ 98 (+151.28%)
Mutual labels:  compliance
Dns Violations
List of DNS violations by implementations, software and/or systems
Stars: ✭ 216 (+453.85%)
Mutual labels:  compliance
forge
ISC Forge is an open source DHCP conformance validation framework, primarily used for testing ISC Kea.
Stars: ✭ 26 (-33.33%)
Mutual labels:  compliance
Binaryanalysis Ng
Binary Analysis Next Generation (BANG)
Stars: ✭ 215 (+451.28%)
Mutual labels:  compliance
openacr
OpenACR is a digital native Accessibility Conformance Report (ACR). The initial development is based on Section 508 requirements. The main goal is to be able to compare the accessibility claims of digital products and services. A structured, self-validated, machine-readable documentation will provide for this.
Stars: ✭ 61 (+56.41%)
Mutual labels:  compliance
intercept
INTERCEPT / Policy as Code Static Analysis Auditing / SAST
Stars: ✭ 54 (+38.46%)
Mutual labels:  compliance
cscanner
An open source, multi-cloud DevSecOps compliance checker
Stars: ✭ 19 (-51.28%)
Mutual labels:  compliance
guardian
Guardian is a tool for extensible and universal data access with automated access workflows and security controls across data stores, analytical systems, and cloud products.
Stars: ✭ 127 (+225.64%)
Mutual labels:  compliance

As of June 21, 2021, the Before You Ship content has been entirely merged into the TTS Handbook. It has also been rebranded as Launching software so as to convey that the tips enclosed should be looked at earlier than right before software is shipped. For more information about this change, see the relevant GitHub issue.


TTS Before You Ship Guide CircleCI

This is the source repository for the TTS Before You Ship guide.

This guide is maintained by the TTS Tech Portfolio team.

Development

See the Usage section of our Contributing guidelines.

Public domain

This project is in the worldwide public domain. As stated in CONTRIBUTING:

This project is in the public domain within the United States, and copyright and related rights in the work worldwide are waived through the CC0 1.0 Universal public domain dedication.

All contributions to this project will be released under the CC0 dedication. By submitting a pull request, you are agreeing to comply with this waiver of copyright interest.

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].