Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONTerraSecure is an ML-powered security scanner for Terraform and HCL Infrastructure as Code across AWS, Azure, and GCP. It detects cloud misconfigurations at build time using a multi-cloud rule engine, an XGBoost ML model for AWS, and AI analysis for contextual remediation, integrating with CI/CD workflows.
Shannon is an open-source, autonomous AI pentester for web applications and APIs. It analyzes your source code to find attack paths, then executes real exploits against a running app, reporting only vulnerabilities proven with a working proof of concept.
Gitleaks is an open-source secret detection tool for scanning git repositories, directories, files and stdin for passwords, API keys and tokens, with pre-commit hook and CI action integrations.
TruffleHog is a Go-based CLI that scans Git, GitHub, GitLab, Docker, S3, GCS, filesystems, CI logs and other sources for leaked credentials; it classifies, verifies and analyzes secrets, with JSON/SARIF output.
Xonsh is a full-featured, cross-platform shell that uses Python 3 as its language, seamlessly integrating shell commands with Python. It runs on Linux, macOS, Windows, BSD, Jupyter, Android, Raspberry Pi, and Nix, with an extension system and AI-friendly features.