
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

A tool to manage vulnerable docker containers

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

A powerful testing tool for Kubernetes clusters.

A tool for secrets management, encryption as a service, and privileged access management

Linting tool for CloudFormation templates

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

Simple and flexible tool for managing secrets

All-in-one tool for managing vulnerability reports from AppSec pipelines

KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems

Infisical is the open-source platform for secrets, certificates, and privileged access management.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …