Preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack. First of all, it's the chicken and the egg. How do you pull a legit preflight binary from us without verifying it with preflight? The best way is to grab the source, compile it yourself, and use your own binary which you put in a place that you trust. People usually have several options of how to do that safely: Put it on your own S3 bucket, Drop it on your own Artifactory or similar, Push it directly into your repos (it should be as small as 4mb and almost never change so Git should work nicely with it), Build from source into your containers directly: FROM golang:1.16-alpine AS preflight_builder RUN apk add --no-cache git WORKDIR /builds RUN GOBIN=`pwd` go get -u github.com/spectralops/preflight # Build from a bare image, copy built binary FROM alpine:3.9 RUN apk add ca-certificates COPY --from=preflight_builder /builds/preflight /usr/local/bin # use preflight as you wish RUN curl https://.. |
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Web-based tool for browsing mobile applications sandbox and previewing SQLite databases.
A data-mining and deep web asset search engine for breach analysis and prevention services.
iOS Reverse Engineering Toolkit for automating common tasks in iOS penetration testing.
Android vulnerability analysis system with efficient scanning and high accuracy.
A tool for quantitative risk analysis of Android applications using machine learning techniques.
An open-source phishing toolkit for businesses and penetration testers.
Extract local data storage of an Android application in one click.
Python tool for monitoring user-select APIs in Android apps using Frida.
An Active Defense framework for detecting and responding to phishing attacks in Office 365 Message Trace logs.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.