ciandcd
Section: secure tools · Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
Entry
Appears in 6 awesome lists
Vulnerability Scanner and Risk Evaluation for containers, serverless and hosts at runtime. ThreatMapper generates runtime BOMs from dependencies and operating system packages, matches against multiple threat feeds, scans for unprotected secrets, and scores issues based on severity and…
Section: secure tools · Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
Section: Dependency Management · Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
Section: Security · Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
Section: Open Source Projects · Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless
Section: Scanning / Pentesting · Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
Section: Multiple languages · Vulnerability Scanner and Risk Evaluation for containers, serverless and hosts at runtime. ThreatMapper generates runtime BOMs from dependencies and operating system packages, matches against multiple threat feeds, scans for unprotected secrets, and scores issues based on severity and…
Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.
script that checks for dozens of common best-practices around deploying Docker containers in production, inspired by the CIS Docker Community Edition Benchmark v1.1.0.
Scans IaC projects for security vulnerabilities, compliance issues, and infrastructure misconfiguration. Currently working with Terraform projects, Kubernetes manifests, Dockerfiles, AWS CloudFormation Templates, and Ansible playbooks.
Sysdig Falco is an open source container security monitor. It can monitor application, container, host, and network activity and alert on unauthorized activity.
Self-hosted sandbox runtime for AI agents with isolated Docker containers, cgroup v2 memory management, and dynamic pressure monitoring.
Extracts network dependencies from Docker Compose, Kubernetes manifests, Helm charts, and other config files to generate Kubernetes NetworkPolicies with evidence tracing.
GitHub - Automatically scan GitHub repositories for vulnerabilities and create pull requests to merge in patched dependencies.
JFrog - Security and compliance analysis for artifacts stored in JFrog Artifactory.