cloud-custodian / cloud-custodian/community

Vulnerable App Before, Secure Env After with c7n

Open
#35 2 comments 0 reactions 1 assignee Claimed by @castrojo View on GitHub
Dominant language
Shell
Stars
10
Forks
5
PR merge metrics
No merged PRs in 30d

Description

Hello @castrojo, during @LiamRandall's Governance-as-Code day talk this afternoon, I suggested an interesting community project would be Liam's vulnerable app and cloud deployment, the PeopleFacts app, or similar projects like [flaws.cloud](https://flaws.cloud), [flaws2.cloud](https://flaws2.cloud), or [cloudgoat](https://github.com/RhinoSecurityLabs/cloudgoat) with a focus on detection and protection with c7n tooling. We can take one of these sample environments with a before and after theme, and the after theme being an assessment with recommended c7n rules to prevent breach.

I am willing to commit some time to this project starting in November and the months following. Let me know how I would need to formulate a plan for review by c7n core devs and/or community members that are here, get buy-in and support for such a plan. If there is limited interest, I can work on it as a separate personal project and update on status here.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.