{"id":41588769,"url":"https://github.com/h4x0r/1-click-github-sec","last_synced_at":"2026-01-24T09:11:02.509Z","repository":{"id":315522725,"uuid":"1059837500","full_name":"h4x0r/1-click-github-sec","owner":"h4x0r","description":"One-click install basic security controls for GitHub-managed projects","archived":false,"fork":false,"pushed_at":"2026-01-12T09:07:43.000Z","size":3965,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-01-12T18:37:56.924Z","etag":null,"topics":["devsecops","security","security-tools"],"latest_commit_sha":null,"homepage":"https://h4x0r.github.io/1-click-github-sec/","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/h4x0r.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"docs/contributing.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/security/architecture.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-09-19T02:52:12.000Z","updated_at":"2025-10-24T12:56:42.000Z","dependencies_parsed_at":"2025-09-24T15:21:31.373Z","dependency_job_id":"8ae5edcd-a972-46e8-a144-ec3845544d49","html_url":"https://github.com/h4x0r/1-click-github-sec","commit_stats":null,"previous_names":["h4x0r/1-click-rust-sec","h4x0r/1-click-github-sec"],"tags_count":26,"template":false,"template_full_name":null,"purl":"pkg:github/h4x0r/1-click-github-sec","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/h4x0r%2F1-click-github-sec","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/h4x0r%2F1-click-github-sec/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/h4x0r%2F1-click-github-sec/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/h4x0r%2F1-click-github-sec/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/h4x0r","download_url":"https://codeload.github.com/h4x0r/1-click-github-sec/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/h4x0r%2F1-click-github-sec/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28722287,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-24T08:27:05.734Z","status":"ssl_error","status_checked_at":"2026-01-24T08:27:01.197Z","response_time":89,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["devsecops","security","security-tools"],"created_at":"2026-01-24T09:11:02.442Z","updated_at":"2026-01-24T09:11:02.497Z","avatar_url":"https://github.com/h4x0r.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 1-Click GitHub Security 🛡️\n\n\u003cdiv align=\"center\"\u003e\n  \u003cimg src=\"docs/1-click-github-sec Logo.png\" alt=\"1-Click GitHub Security\" width=\"200\"\u003e\n\u003c/div\u003e\n\n**Deploy security controls to any project in one command**\n\n*Security that auto-fixes problems instead of just complaining about them*\n\n*Created by Albert Hui \u003calbert@securityronin.com\u003e* [![LinkedIn](https://img.shields.io/badge/LinkedIn-0077B5?style=flat-square\u0026logo=linkedin\u0026logoColor=white)](https://www.linkedin.com/in/alberthui) [![Website](https://img.shields.io/badge/Website-4285F4?style=flat-square\u0026logo=google-chrome\u0026logoColor=white)](https://www.securityronin.com/)\n\nSupports **Rust, Node.js, Python, Go, and generic projects** with 35+ security controls including pre-push validation, CI/CD workflows, and GitHub security features.\n\n**📊 [Executive Briefing](docs/executive-briefing.md)** | **📚 [Documentation](https://h4x0r.github.io/1-click-github-sec/)** | **🏗️ [Architecture](docs/architecture.md)**\n\n[![Security](https://img.shields.io/badge/Installer%20Provides-35%2B%20Controls-green.svg)](https://h4x0r.github.io/1-click-github-sec/) [![GitHub Integration](https://img.shields.io/badge/Works%20with-GitHub-181717?logo=github\u0026logoColor=white)](https://docs.github.com/en/rest) [![GitHub Security](https://img.shields.io/badge/GitHub%20Security-6%20Features-blue.svg)](https://h4x0r.github.io/1-click-github-sec/) [![Performance](https://img.shields.io/badge/Pre--Push-%3C60s-orange.svg)](https://h4x0r.github.io/1-click-github-sec/) [![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](LICENSE) [![Version](https://img.shields.io/badge/Version-v0.7.0-purple.svg)](https://github.com/h4x0r/1-click-github-sec/releases)\n\n---\n\n## 🎯 What You Get\n\n### Pre-Push Security (\u003c 60 seconds)\n✅ **Secret detection** - Blocks API keys, passwords, tokens\n✅ **Vulnerability scanning** - Catches known security issues\n✅ **Code quality checks** - Language-specific linting\n✅ **Test validation** - Ensures tests pass before push\n✅ **Supply chain security** - SHA pinning, dependency validation\n\n### CI/CD Workflows (Comprehensive Analysis)\n🔍 **Static analysis** - SAST with CodeQL and Trivy\n🔍 **Dependency auditing** - Automated vulnerability detection\n🔍 **Security reporting** - SBOM generation and metrics\n🔍 **Compliance checking** - License and policy validation\n\n### GitHub Security Features (Automated Setup)\n🤖 **Renovate** - Automated dependency updates with automerge\n🔐 **Secret scanning** - Repository-wide credential detection\n🔐 **Branch protection** - Enforce security policies\n🔐 **Security advisories** - Vulnerability disclosure workflow\n\n---\n\n## 🧠 Design Philosophy: Don't Make Me Think (DMMT)\n\n**Security that works like a UK power plug - impossible to do wrong, automatic to do right.**\n\nOur DMMT principle means:\n- **🛠 Auto-fixes instead of errors** - We fix SHA pinning automatically, not just complain\n- **⚡ Zero configuration required** - Sensible defaults that work immediately\n- **🎯 One command, comprehensive security** - No manual setup or integration\n- **✨ Invisible when working** - Security runs in background, visible only when needed\n- **🔧 Graceful degradation** - Partial features better than complete failure\n\n**Example:** Instead of `\"Error: Action not pinned\"`, you see `\"✅ Auto-pinned actions/checkout@v4 → @08eba0b2\"`\n\nThis isn't just convenient - it's security through design. Like the UK plug that physically prevents incorrect insertion, we make insecure practices impossible rather than merely discouraged.\n\n---\n\n## 🚀 Quick Start\n\n**Install security controls in your project:**\n\n```bash\n# Download installer and SLSA provenance\ncurl -O https://github.com/h4x0r/1-click-github-sec/releases/download/v0.7.0/install-security-controls.sh\ncurl -O https://github.com/h4x0r/1-click-github-sec/releases/download/v0.7.0/multiple.intoto.jsonl\n\n# VERIFY with SLSA provenance (cryptographic proof of authenticity)\n# Install slsa-verifier: https://github.com/slsa-framework/slsa-verifier#installation\nslsa-verifier verify-artifact \\\n  --provenance-path multiple.intoto.jsonl \\\n  --source-uri github.com/h4x0r/1-click-github-sec \\\n  install-security-controls.sh\n\n# Install after verification\nchmod +x install-security-controls.sh\n./install-security-controls.sh\n```\n\n**Python projects:** Activate your environment first for optimal tool installation:\n```bash\n# conda/miniconda\nconda activate myproject\n\n# pyenv/asdf/mise\npyenv local 3.11.0  # or: mise use python@3.11\n\n# virtual environment\nsource venv/bin/activate\n\n# Then run installer\n./install-security-controls.sh\n```\n\n**That's it!** Your project now has comprehensive security controls with cryptographic verification!\n\nNo configuration files to edit. No tools to manually install. No documentation to read. **It just works.**\n\n**Why verify?** Every release is cryptographically signed with SLSA Build Level 3 provenance - proving it wasn't tampered with. [Learn more →](https://h4x0r.github.io/1-click-github-sec/cryptographic-verification)\n\n---\n\n## 📖 Complete Documentation\n\n**👉 [Visit Documentation Site](https://h4x0r.github.io/1-click-github-sec/) 👈**\n\n### 🚀 New Users\n- **[Quick Start](https://h4x0r.github.io/1-click-github-sec/)** - Get running in 5 minutes\n- **[Installation Guide](https://h4x0r.github.io/1-click-github-sec/installation)** - Detailed setup instructions\n- **[Upgrading Guide](docs/UPGRADING.md)** - Upgrade to latest version (v0.9.0+ features config-driven workflow generation)\n\n### 🔧 Power Users\n- **[Security Architecture](https://h4x0r.github.io/1-click-github-sec/architecture)** - How everything works\n- **[GitHub Enterprise vs Free](https://h4x0r.github.io/1-click-github-sec/github-enterprise-comparison)** - Feature availability and alternatives\n- **[Complete Signing Guide](https://h4x0r.github.io/1-click-github-sec/signing-guide)** - 4-mode setup, GPG vs gitsign, verification\n- **[Cryptographic Verification](https://h4x0r.github.io/1-click-github-sec/cryptographic-verification)** - Advanced verification procedures\n\n### 👥 Contributors\n- **[Contributing Guide](https://github.com/h4x0r/1-click-github-sec/blob/main/docs/contributing.md)** - Development setup\n- **[Repository Security \u0026 Quality Assurance](https://github.com/h4x0r/1-click-github-sec/blob/main/docs/repo-security-and-quality-assurance.md)** - This repo's implementation\n- **[Design Principles](https://github.com/h4x0r/1-click-github-sec/blob/main/docs/design-principles.md)** - Architectural decisions\n\n### 📊 Leadership\n- **[Executive Briefing](https://h4x0r.github.io/1-click-github-sec/executive-briefing)** - Strategic evaluation for CTOs, VPs, Directors\n\n---\n\n## 📊 This Repository vs Your Project\n\nThis repository demonstrates \"dogfooding plus\" - it uses enhanced security controls beyond what it installs:\n\n| Feature | What Installer Gives You | What This Repository Has |\n|---------|-------------------------|--------------------------|\n| **Pre-push Controls** | 24 universal security checks | 24 security checks + 5 development-specific |\n| **CI/CD Workflows** | Optional installation | 6 specialized development workflows |\n| **GitHub Security** | Automated setup | Enhanced with custom policies |\n| **Documentation** | Installation guides | Complete documentation site + development controls documentation |\n| **Cryptographic Signing** | Optional setup | All commits \u0026 releases signed |\n\n**Bottom line:** We use an enhanced version of what we provide to others, proving it works in production.\n\n---\n\n## 💬 Support \u0026 Community\n\n- **🐛 [Report Issues](https://github.com/h4x0r/1-click-github-sec/issues)** - Bug reports and feature requests\n- **📖 [Documentation](https://h4x0r.github.io/1-click-github-sec/)** - Comprehensive guides and references\n- **🔄 [Releases](https://github.com/h4x0r/1-click-github-sec/releases)** - Download latest version\n- **🤝 [Contributing](https://github.com/h4x0r/1-click-github-sec/blob/main/docs/contributing.md)** - Help improve the project\n\n---\n\n## 📄 License\n\nLicensed under the Apache License, Version 2.0. See [LICENSE](LICENSE) for details.\n\n---\n\n**🛡️ Secure by default. Simple by design. Verified by cryptography.**","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fh4x0r%2F1-click-github-sec","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fh4x0r%2F1-click-github-sec","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fh4x0r%2F1-click-github-sec/lists"}