Skip to content

Entry

syft

Appears in 6 awesome lists

star:8295 A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

Open github.comanchore/syft

Found in these lists

Awesome Cloud Native

Section: Security & Compliance · CLI tool and library for generating a Software Bill of Materials from container images and filesystems.

FreshScore 87

Awesome Devsecops

Section: Supply Chain Security · Anchore - A CLI tool for generating a Software Bill of Materials (SBOM) from container images and filesystems.

StaleScore 52

Awesome Docker

Section: Image Scanning & SBOM · CLI tool and library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

FreshScore 92

Awesome Go

Section: Package Management · A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

FreshScore 94

Awesome Go

Section: 包管理 · star:8295 A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

FreshScore 89

awesome-go

Section: Security Tools · CLI tool and library for generating a Software Bill of Materials from container images and filesystems

FreshScore 81

Darkmoon

🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…

In 10 listsDetails

Trivy

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.

In 9 listsDetails

Keycloak

🆓 Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password policies.

In 7 listsDetails

Checkov

Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

In 7 listsDetails

brood-box

🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…

In 6 listsDetails

cosign

Container signing, verification, and transparency log for OCI artifacts.

In 6 listsDetails

Pomerium

Pomerium is a zero-trust context and identity aware access gateway inspired by BeyondCorp.

In 6 listsDetails

hashicorp/vault

A tool for securely accessing secrets. A secret is anything that you want to tightly control access to, such as API keys, passwords, certificates, and more.

In 7 listsDetails