
cved
A tool to manage vulnerable docker containers

A tool to manage vulnerable docker containers
Low-level unprivileged sandboxing tool used by Flatpak and similar projects

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Chaos testing, network emulation, and stress testing tool for containers

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

cve-unassigned-1

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Pentester-focused Docker registry tool to enumerate and pull images

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

The easiest, and most secure way to access and protect all of your infrastructure.

Code signing and transparency for containers and binaries

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…