Skip to content

Entry

Checkov

Appears in 7 awesome lists

Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

Open github.combridgecrewio/checkov

Found in these lists

Awesome AWS

Section: Security · Terraform static analysis, verifies security best practices.

StaleScore 58

Awesome Cloud Native

Section: Security & Compliance · A static analysis tool for infrastructure as code - to prevent misconfigs at build time.

FreshScore 87

Awesome Devsecops

Section: Infrastructure as Code Analysis · Bridgecrew - Scan Terraform, AWS CloudFormation and Kubernetes templates for insecure configuration.

StaleScore 52

Awesome Docker

Section: Security · Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

FreshScore 92

Awesome Security

Section: Development · A static analysis tool for infrastucture as code (Terraform).

SlowScore 70

Awesome Terraform

Section: Tools · Terraform static analysis tool for terraform>=0.12

FreshScore 89

Awesome DevOps

Section: Security · Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages.

FreshScore 87

Algo

Set up a DIY/personal VPN in the cloud. It is a set of Ansible scripts that simplify the setup of a personal WireGuard and IPsec VPN, open-sourced by Trail of Bits. :green_circle:

In 12 listsDetails

Darkmoon

🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…

In 10 listsDetails

Trivy

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.

In 9 listsDetails

Keycloak

🆓 Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password policies.

In 7 listsDetails

brood-box

🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…

In 6 listsDetails

syft

star:8295 A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

In 6 listsDetails

cosign

Container signing, verification, and transparency log for OCI artifacts.

In 6 listsDetails

Pomerium

Pomerium is a zero-trust context and identity aware access gateway inspired by BeyondCorp.

In 6 listsDetails