diff --git a/README.md b/README.md index d1424bb1..d9717238 100644 --- a/README.md +++ b/README.md @@ -1,8 +1,3 @@ -
- - Legitify Logo - -
[![Build & Test](https://github.com/Legit-Labs/legitify/actions/workflows/build_and_test.yaml/badge.svg)](https://github.com/Legit-Labs/legitify/actions/workflows/build_and_test.yaml) @@ -10,23 +5,24 @@ [![Version Releaser](https://github.com/Legit-Labs/legitify/actions/workflows/release.yaml/badge.svg)](https://github.com/Legit-Labs/legitify/actions/workflows/release.yaml) [![Build Docs](https://github.com/Legit-Labs/legitify/actions/workflows/build_docs.yaml/badge.svg)](https://github.com/Legit-Labs/legitify/actions/workflows/build_docs.yaml) [![Go Report Card](https://goreportcard.com/badge/github.com/Legit-Labs/legitify)](https://goreportcard.com/report/github.com/Legit-Labs/legitify) -[![Maintained By Legit Security](https://img.shields.io/badge/Maintained%20by-Legit%20Security-blueviolet)](https://www.legitsecurity.com/)
Legitify Logo - + Strengthen the security posture of your source-code management!
Detect and remediate misconfigurations, security and compliance issues across all your GitHub and GitLab assets with ease 🔥
- by [Legit Security](https://www.legitsecurity.com/). +by [Legit Security](https://www.legitsecurity.com/). Wonder what Legit Security does? -We do ASPM and software supply chain security, for more information check out the [comparison table](#legitify-vs-the-legit-security-platform) +Legit Security is an application security posture management (ASPM) and software supply chain security solution.
+For more information check out the [comparison table](#legitify-vs-the-legit-security-platform)
+ https://user-images.githubusercontent.com/107790206/210602039-2d022692-87ea-4005-b9c6-f091158de3ce.mov ## Installation @@ -313,20 +309,19 @@ If you liked Legitify, you are going to love the Legit Security Platform! Below is a comfeature parison between Legitify and Legit: -| **Capability** | **Legitify** | **Legit Security Platform** | -| --------------------------- | ------------------------------------------------------------------------------------------ | ------------------------------------------------ | -| Supported Platforms | GitHub cloud & server
Gitlab cloud & server | ALL Major SCMs (incl. Azure DevOps, Bitbucket and more)
CI/CD systems (e.g. Jenkins)
Package Registries (e.g. JFrog Artifactory | -| Risk detection | SCM's Misconfigurations only | SCM's Misconfigurations
CI Misconfigurations
CD Misconfigurations
Package Registries Misconfigurations
Pipeline risks
Secrets
IaC
Security Incidents
And more...| -| SDLC asset management | - | Yes | -| Compliance Report | [OSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/) | SSDF
SLSA
SOC2
ISO 27001
FedRAMP
and more...| -| Issue & Policy Management | - | Yes | -| Contextualized Information | No Context | Prioritize issues with contextualized information through Legit's Code To Cloud technology | -| Custom policies | - | Yes | -| Policy drifts detection | - | Yes | +| **Capability** | **Legitify** | **Legit Security Platform** | +|---|---|---| +| Supported platforms | GitHub
GitLab | ALL major SCMs (incl. Azure DevOps, Bitbucket and more)
CI/CD systems (e.g. Jenkins)
Package registries (e.g. JFrog Artifactory)
Cloud providers (e.g. AWS) | +| Risk detection | SCM Misconfigurations only | SCMs Misconfigurations
CI Misconfigurations
CD Misconfigurations
Package Registries Misconfigurations
Pipeline risks
Secrets
IaC
Security Incidents
And more... | +| Compliance report | [OSSF SCM Best Practices](https://best.openssf.org/SCM-BestPractices/) | SSDF
SLSA
SOC2
ISO 27001
FedRAMP
And more... | +| Policy drifts detection | Can be detected periodically though Legitify's GitHub Action | Get real-time alerts when a misconfiguration is introduced | +| SDLC assets management | - | Yes | +| Issue & policy management | - | Yes | +| Code To Cloud context | - | Yes (contextualized information enables smarter prioritization) | | Workspaces & product groups | - | Yes | -| Ticketing & Alerting | - | Jira, Slack, etc. | -| Ingest risk | - | Import APIs and integrations with SAST, SCA and other testing solutions | -| Rest APIs | -| Yes | +| Ticketing & alerting | - | Jira, Slack, and more | +| Ingest risk | - | Import APIs and integrations with SAST, SCA and other testing solutions | +| Rest APIs | - | Yes | To check out Legit, visit our [website](https://www.legitsecurity.com/) or directly [book a demo](https://info.legitsecurity.com/book-a-demo)