
trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

An open source real-time network topology and protocols analyzer

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

Protect against malicious open source packages 🤖

Getting a handle on container security

Real-time, container-based file scanning at enterprise scale

Metarget is a framework providing automatic constructions of vulnerable infrastructures.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Linux应急处置/信息搜集/漏洞检测工具,支持基础配置/网络流量/任务计划/环境变量/用户信息/Services/bash/恶意文件/内核Rootkit/SSH/Webshell/挖矿文件/挖矿进程/供应链/服务器风险等13类70+项检查

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.