
semgrep-rules
Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

eBPF-powered Kubernetes monitoring and performance testing platform that automatically generates service maps, tracks real-time metrics, and runs…

Snyk CLI scans and monitors your projects for security vulnerabilities.

Hardened, Azure-optimized Linux distribution built from Fedora sources with RPM packaging, supply chain security, and declarative configuration for…

An open source real-time network topology and protocols analyzer

AWSGoat : A Damn Vulnerable AWS Infrastructure

kubeaudit helps you audit your Kubernetes clusters against common security controls

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

kube-scan: Octarine k8s cluster risk assessment tool

Getting a handle on container security

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

A software supply chain framework powered by Nix.

the ps utility, with an eBPF twist and container context