
syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Protect against malicious open source packages 🤖

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

A vulnerability scanner for container images and filesystems

Library and CLI tool for analysing CloudFormation templates and check them for security compliance.

Open-source secret scanner in Rust

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Kubernetes RBAC static analysis & visualisation tool

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Write tests against structured configuration data using the Open Policy Agent Rego query language

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Vulnerability Static Analysis for Containers

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…