
ansible-mitigate-copyfail-dirtyfrag
Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.

Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.

DaemonSet для митигации уязвимости CVE-2026-64564 (SCTPhantom)

Kubernetes DaemonSet to detect and remediate CVE-2026-31431 (GHSA-2274-3hgr-wxv6) — algif_aead LPE via modprobe blacklist

Ansible role that applies and verifies the modprobe.d mitigation for CVE-2026-31431 by disabling the algif_aead kernel module, with safety checks for…

Automates kernel patching for CVE-2026-31431 and Dirty Frag, sets secure kernel as default in GRUB, and disables testing repo for production safety.

Salt state to deploy a mitigation of the copy.fail vulnerability (CVE-2026-31431)

دستورالعملهای کاهش ریسک و بهروزرسانی برای CVE-2026-31431 در سیستمهای اوبونتو، شامل مراحل ارتقاء کرنل و kmod.

Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7

Secure and fast microVMs for serverless computing.

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from…

Infrastructure as code for DNS!

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf,…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

An open source, cloud-native security to protect everything from build to runtime

GCPGoat : A Damn Vulnerable GCP Infrastructure

This chef cookbook provides secure ssh-client and ssh-server configurations.