Skip to content
Change the repository type filter

All

    Repositories list

    • Open Cyber Threat Intelligence Platform
      TypeScript
      1.2k000Updated Sep 25, 2025Sep 25, 2025
    • Securing Alice's, Bob's and Carl's software supply chain using in-toto
      Python
      42000Updated Sep 5, 2025Sep 5, 2025
    • 🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
      Go
      8000Updated Sep 2, 2025Sep 2, 2025
    • CLI tool and library for generating a Software Bill of Materials from container images and filesystems
      Go
      741000Updated Aug 10, 2025Aug 10, 2025
    • A vulnerability scanner for container images and filesystems
      Go
      713000Updated Jul 15, 2025Jul 15, 2025
    • Language-agnostic SLSA provenance generation for Github Actions
      Go
      171000Updated Jun 27, 2025Jun 27, 2025
    • Vault Plugin for Gitlab Access Tokens
      Go
      12000Updated Jun 7, 2025Jun 7, 2025
    • Runnable examples in Go of how to integrate an application with HashiCorp Vault.
      Go
      34000Updated Apr 17, 2025Apr 17, 2025
    • For engineers and security teams driving fast and secure software supply chains
      24000Updated Feb 16, 2025Feb 16, 2025
    • Venafi CodeSign Protect Golang CLI and SDK
      Go
      2000Updated Feb 14, 2025Feb 14, 2025
    • Add/verify Advanced Electronic Signature (AES) and Qualified Electronic Signature (QES) in PDF (usign pure Go)
      Go
      34000Updated Feb 10, 2025Feb 10, 2025
    • Signature Discovery Utility
      Go
      3000Updated Feb 10, 2025Feb 10, 2025
    • Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
      Go
      2.8k000Updated Feb 6, 2025Feb 6, 2025
    • Supply-chain Levels for Software Artifacts
      Shell
      272000Updated Feb 4, 2025Feb 4, 2025
    • The Kubernetes Security Profiles Operator
      C
      125000Updated Jan 31, 2025Jan 31, 2025
    • Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
      Python
      1.9k000Updated Jan 18, 2025Jan 18, 2025
    • Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
      Python
      1.3k000Updated Jan 5, 2025Jan 5, 2025
    • Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
      Python
      1.3k000Updated Dec 31, 2024Dec 31, 2024
    • 📚 The OPA Gatekeeper policy library
      Open Policy Agent
      339000Updated Dec 30, 2024Dec 30, 2024
    • Secure your apps by making them Secretless
      Go
      49000Updated Dec 18, 2024Dec 18, 2024
    • 15000Updated Jul 26, 2024Jul 26, 2024
    • spicedb

      Public
      Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications
      Go
      355000Updated Jul 7, 2024Jul 7, 2024
    • SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
      PHP
      25k000Updated Apr 27, 2024Apr 27, 2024
    • GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
      HTML
      1.5k000Updated Apr 8, 2024Apr 8, 2024
    • PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
      C#
      3.3k000Updated Apr 8, 2024Apr 8, 2024
    • A list of useful payloads and bypass for Web Application Security and Pentest/CTF
      Python
      16k000Updated Apr 6, 2024Apr 6, 2024
    • bane

      Public
      Custom & better AppArmor profile generator for Docker containers.
      Go
      90100Updated Apr 5, 2024Apr 5, 2024
    • OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
      TypeScript
      16k000Updated Apr 5, 2024Apr 5, 2024
    • hydra
      C
      2.4k000Updated Apr 1, 2024Apr 1, 2024
    • trivy

      Public
      Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
      Go
      2.8k000Updated Mar 23, 2024Mar 23, 2024