Showing 36 of 57 projects
A comprehensive security scanner that finds vulnerabilities, misconfigurations, secrets, and SBOMs in containers, Kubernetes, code, and clouds.
A tool for detecting secrets like passwords, API keys, and tokens in git repositories, directories, and stdin.
A secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across multiple sources.
A secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across multiple sources.
An automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis, and security assessment framework.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
An open-source cloud security platform that automates security and compliance assessments across AWS, Azure, GCP, and other cloud providers.
A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.
A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.
Static vulnerability analysis for container images (OCI/Docker) via an API that indexes and matches against known security flaws.
Open-source vulnerability static analysis tool for container images (OCI/Docker) via API-based indexing and matching.
A script that checks for dozens of common best-practices around deploying Docker containers in production.
Standard libraries and queries for CodeQL, powering GitHub Advanced Security and static application security testing.
A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.
A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.
A static analysis tool that scans Go source code for security vulnerabilities by analyzing the AST and SSA representations.
A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.
A static analysis security vulnerability scanner for Ruby on Rails applications.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A curated list of books, articles, websites, and tools for learning application security across multiple programming languages.
A curated list of books, articles, websites, and tools for learning application security across multiple programming languages.
A curated collection of security hardening guides, best practices, checklists, benchmarks, and tools for various systems and services.
A static analysis framework for Solidity and Vyper smart contracts that detects vulnerabilities, enhances code comprehension, and enables custom analyses.
A tool for signing and verifying container images and other artifacts using the Sigstore framework.
An intentionally vulnerable Kubernetes cluster environment for hands-on security training and practice.
Automated security health metrics for open source projects, assessing security best practices and risks.
Open source CNAPP that hunts for threats in cloud native platforms, ranks them by risk, and visualizes attack paths.
A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.
An enterprise-friendly Python tool for detecting and preventing secrets from entering codebases with a baseline approach.
A static analysis tool that finds security vulnerabilities and misconfigurations in GitHub Actions workflows.
A security auditing tool for SSH server and client configurations, analyzing algorithms, vulnerabilities, and policy compliance.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.