{"repo":"Legit-Labs/legitify","free":true,"listed":false,"github":"https://github.com/Legit-Labs/legitify","clone":"git clone https://github.com/Legit-Labs/legitify.git","description":"Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets","language":"Go","stars":881,"topics":["supply-chain-security","security-scanner","sdlc-security","devops","security","devsecops","ci","github","gitlab","golang"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Strengthen the security posture of your source-code management! Detect and remediate misconfigurations, security and compliance issues across all your GitHub and GitLab assets with ease 🔥 by Legit Security. Wonder what Legit Security does? Legit Security is an application security posture management (ASPM) and software supply chain security solution. For more information check out the comparison table https://user-images.githubusercontent.com/107790206/210602039-2d022692-87ea-4005-b9c6-f091158de3ce.mov Installation Installation is possible in several ways: - For macOS (or linux) using homebrew: - You can download the latest legitify release from https://github.com/Legit-Labs/legitify/releases, each archive contains: - Legitify binary for the desired platform - Built-in policies provided by Legit Security - From source with the following steps: - As a GitHub CLI extension (check out https://github.com/Legit-Labs/gh-legitify for more information) CI - Legitify Custom GitHub Action You can run legitify as part of a CI process with the legitify Custom GitHub Actions: Checkout the action file for additional parameters and configuration. Provenance To enhance the software supply chain security of legitify's users, as of v0.1.6, every legitify release contains a SLSA Level 3 Provenance document. The provenance document refers to all artifacts in the release, as well as the generated docker image. You can use SLSA framework's official verifier to verify the provenance. Example of us","default_branch":null,"files":null,"tree":[],"storefront":"/r/Legit-Labs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Legit-Labs/legitify/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}