
agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

An embeddable, portable, branchable virtual machine to safely run Agents locally.

Snyk CLI scans and monitors your projects for security vulnerabilities.

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

A durable process per agent, with memory that survives restarts

Generates SCAP, Ansible, Bash, and CEL security content for compliance evaluation and automated hardening across Linux hosts, containers, and…

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

☸️ The Open Testing Platform for AI-Driven Engineering Teams

Minimal CVE Hardened container image collection

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Runtime Security Enforcement System. Workload hardening/sandboxing and implementing least-permissive policies made easy leveraging LSMs (LSM-BPF,…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Proper sandboxing for agentic coding and web browsing

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.