Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Compliance

Compliance

36 projects

Showing 36 of 36 projects

lynis
lynisShell

A security auditing and hardening tool for UNIX-based systems, performing in-depth scans and compliance testing.

#system-hardening#hipaa#unix
Stars15.5k
Forks1.6k
Last commit2 months ago
wazuh
wazuhC++

An open-source unified XDR and SIEM platform for threat prevention, detection, and response across endpoints and cloud workloads.

#container-security#siem#malware-detection
Stars15.4k
Forks2.3k
Last commit1 day ago
prowler
prowlerPython

An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.

#aws-security#infrastructure-security#multi-cloud
Stars13.7k
Forks2.1k
Last commit1 day ago
Prowler
ProwlerPython

An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.

#aws-security#infrastructure-security#multi-cloud
Stars13.7k
Forks2.1k
Last commit1 day ago
docuseal
docusealRuby

Open source platform for creating, filling, and signing digital documents with an easy-to-use, mobile-optimized web tool.

#documents#open-source#workflow-automation
Stars11.8k
Forks1.0k
Last commit4 days ago
Open Policy Agent
Open Policy AgentGo

An open-source, general-purpose policy engine for unified, context-aware policy enforcement across the stack.

#declarative#policy-engine#cncf
Stars11.6k
Forks1.6k
Last commit1 day ago
Sigma
SigmaPython

A generic and open signature format for describing log event detections, shareable across SIEM systems.

#signatures#yaml#siem
Stars10.4k
Forks2.6k
Last commit3 days ago
Docker bench security
Docker bench securityShell

A script that checks for dozens of common best-practices around deploying Docker containers in production.

#container-security#audit#security
Stars9.6k
Forks1.0k
Last commit1 year ago
immudb
immudbGo

An immutable database with built-in cryptographic proof and verification, supporting SQL, Key-Value, and Document models.

#zero-trust#database#document-database
Stars9.0k
Forks362
Last commit1 day ago
syft
syftGo

A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.

#sbom#container-security#cyclonedx
Stars8.8k
Forks836
Last commit1 day ago
Syft
SyftGo

A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.

#sbom#container-security#cyclonedx
Stars8.8k
Forks836
Last commit1 day ago
Checkov
CheckovPython

A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.

#aws-security#azure#static-code-analysis
Stars8.7k
Forks1.3k
Last commit3 days ago
checkov
checkovPython

A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.

#aws-security#azure#kubernetes
Stars8.7k
Forks1.3k
Last commit3 days ago
tfsec
tfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#multi-cloud#azure
Stars7.0k
Forks556
Last commit1 month ago
TFSec
TFSecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#multi-cloud#azure
Stars7.0k
Forks556
Last commit1 month ago
tfsec
tfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#azure#terraform-security
Stars7.0k
Forks556
Last commit1 month ago
Tfsec
TfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#rego#google-cloud-platform#multi-cloud
Stars7.0k
Forks556
Last commit1 month ago
Fleet device management
Fleet device managementGo

Open-source platform for IT and security teams to manage and secure thousands of computers across diverse environments.

#osquery#vulnerability-management#it-security
Stars6.3k
Forks846
Last commit1 day ago
Awesome Security Hardening
Awesome Security Hardening

A curated collection of security hardening guides, best practices, checklists, benchmarks, and tools for various systems and services.

#infrastructure-security#windows-hardening#infosec
Stars6.3k
Forks646
Last commit1 month ago
cloud-custodian
cloud-custodianPython

A rules engine for cloud security, cost optimization, and governance using YAML policies to query, filter, and act on cloud resources.

#multi-cloud#cloud-governance#rules-engine
Stars6.0k
Forks1.6k
Last commit1 day ago
terrascan
terrascanGo

A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.

#devops#terrascan#policy-as-code
Stars5.2k
Forks550
Last commit5 months ago
Terrascan
TerrascanGo

A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.

#devops#terrascan#kubernetes
Stars5.2k
Forks550
Last commit5 months ago
OSSEC
OSSECC

Open Source Host-based Intrusion Detection System performing log analysis, file integrity checking, rootkit detection, and active response.

#real-time-alerting#siem#policy-monitoring
Stars5.0k
Forks1.1k
Last commit4 days ago
JSON Schema
JSON SchemaPHP

A PHP implementation for validating JSON structures against JSON Schema drafts 3, 4, 6, and 7.

#php-library#schema#schema-validation
Stars3.6k
Forks369
Last commit3 days ago
Audited
AuditedRuby

An ActiveRecord extension for Rails that logs all changes to your models, including who made them and why.

#rails#audit#ruby-gem
Stars3.5k
Forks663
Last commit5 months ago
Laravel Auditing
Laravel AuditingPHP

A Laravel package that records change logs from Eloquent models to track discrepancies and anomalies.

#eloquent#change-log#lumen
Stars3.4k
Forks403
Last commit7 days ago
Bearer
BearerGo

Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.6k
Forks143
Last commit4 days ago
Bearer
BearerGo

A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.6k
Forks143
Last commit4 days ago
KICS
KICSOpen Policy Agent

KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.

#hacktoberfest#kubernetes#security-scanning
Stars2.6k
Forks363
Last commit2 days ago
Ballerine
BallerineTypeScript

Open-source infrastructure and data orchestration platform for risk decisioning, automating KYC, KYB, underwriting, and transaction monitoring.

#back-office#data-orchestration#workflow-engine
Stars2.4k
Forks291
Last commit1 day ago
OWASP MASVS
OWASP MASVSPython

The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.

#app-security#mobile-security#standard
Stars2.4k
Forks663
Last commit4 months ago
Medplum
MedplumTypeScript

A developer platform for building compliant healthcare applications with FHIR standards, authentication, and clinical data management.

#oauth#developer-platform#hipaa
Stars2.3k
Forks754
Last commit1 day ago
Linux auditd Detection Ruleset
Linux auditd Detection RulesetShell

A production-ready auditd configuration for Linux security monitoring that works out-of-the-box across major distributions.

#security-hardening#linux-security#auditd-configuration
Stars1.8k
Forks302
Last commit2 days ago
openscap
openscapXSLT

A command-line toolkit for validating, scanning, and managing SCAP (Security Content Automation Protocol) documents.

#scanning#scap-toolkit#command-line-tool
Stars1.7k
Forks429
Last commit2 days ago
Greenmask
GreenmaskGo

An open-source tool for PostgreSQL and MySQL database anonymization, synthetic data generation, and logical dumping.

#logical-backup#devops#database-subsetting
Stars1.7k
Forks56
Last commit3 days ago
Grafeas
GrafeasGo

An open-source artifact metadata API for auditing and governing software supply chains.

#container-security#api#software-supply-chain
Stars1.6k
Forks306
Last commit28 days ago

Related Tags

#Security20#Devsecops16#Cloud Security13#Static Analysis13#Aws11#Infrastructure As Code11#Security Scanning11#Security Tools9#Terraform9#Docker7#Azure7#Multi Cloud6
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub