Skip to content

Entry

Open Policy Agent

Appears in 4 awesome lists

🆓 An open-source general-purpose decision engine to create and enforce ABAC policies.

Open github.comopen-policy-agent/opa

Found in these lists

Awesome Cloud Native

Section: Security & Compliance · An open source project to policy-enable your service.

FreshScore 87

Awesome Iam

Section: ABAC frameworks · 🆓 An open-source general-purpose decision engine to create and enforce ABAC policies.

FreshScore 86

go-awesome

Section: 微服务 · 通用策略引擎,CNCF 孵化项目

StaleScore 56

awesome-go

Section: Other · Open Policy Agent (OPA) is an open source, general-purpose policy engine.

FreshScore 81

Darkmoon

🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…

In 10 listsDetails

Trivy

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.

In 9 listsDetails

Keycloak

🆓 Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password policies.

In 7 listsDetails

Checkov

Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

In 7 listsDetails

brood-box

🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…

In 6 listsDetails

syft

star:8295 A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

In 6 listsDetails

go-kit

Microservice toolkit with support for service discovery, load balancing, pluggable transports, request tracking, etc.

In 6 listsDetails

cosign

Container signing, verification, and transparency log for OCI artifacts.

In 6 listsDetails