
trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

safe execution paths for agents - zero trust, zero setup, zero latency.

Protect against malicious open source packages 🤖

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Vulnerability Static Analysis for Containers

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

a guard that blocks catastrophic agent actions

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A project security/vulnerability/risk scanning tool