Awesome Cloud Native
Section: Security & Compliance · Vulnerability Static Analysis for Containers.
Entry
Appears in 6 awesome lists
is an open source project for the static analysis of vulnerabilities in application containers (currently including OCI and Docker).
Section: Security & Compliance · Vulnerability Static Analysis for Containers.
Section: Infrastructure as Code Analysis · Red Hat - Scan App Container and Docker containers for publicly disclosed vulnerabilities.
Section: Image Scanning & SBOM · Clair is an open source project for the static analysis of vulnerabilities in appc and docker containers.
Section: Go · Vulnerability Static Analysis for Containers
Section: Containers · is an open source project for the static analysis of vulnerabilities in application containers (currently including OCI and Docker).
Section: Security Tools · Vulnerability Static Analysis for Containers
🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…
A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.
🆓 Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password policies.
Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.
🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…