Script that checks for dozens of common best-practices around deploying Docker containers in production.
ShellApache License 2.0active
10 projectsSecurity
Script that checks for dozens of common best-practices around deploying Docker containers in production.
ShellApache License 2.0active
Sysdig Falco is an open source container security monitor. It can monitor application, container, host, and network activity and alert on unauthorized activity.
C++Apache License 2.0active
Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.
PythonApache License 2.0active
Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
TypeScriptApache License 2.0active
HAProxy-based fine-grained filter for the Docker API socket; widely used to expose a restricted socket to reverse proxies and homelab stacks.
PythonApache License 2.0active
Forensic utility to explore Docker and containerd container details from mounted disk images.
GoApache License 2.0active
CetusGuard is a tool that protects the Docker daemon socket by filtering calls to its API endpoints.
GoMIT Licensesteady
Lints Docker Compose files for security misconfigurations — privileged containers, unpinned images, Docker socket mounts, plaintext credentials — grounded in OWASP and the CIS Docker Benchmark.
PythonMIT Licenseactive
Extracts network dependencies from Docker Compose, Kubernetes manifests, Helm charts, and other config files to generate Kubernetes NetworkPolicies with evidence tracing.
GoMIT Licensesteady
Self-hosted sandbox runtime for AI agents with Docker containers, security hardening, REST API and WebSocket support.
GoGNU Affero General Public License v3.0active