
syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Minimal CVE Hardened container image collection

A vulnerability scanner for container images and filesystems

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Vulnerable app with examples showing how to not use secrets

Protect against malicious open source packages 🤖

A repo to automatically generate and keep updated a series of Docker images through GitHub Actions.

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

An egress firewall for untrusted workloads.

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Vulnerability Static Analysis for Containers

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Zero-downtime Linux kernel zero-day defense case study. For the automated CLI and dual-witness notary framework, see mc493/kshield.

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.