awesome-repositories.comالتصنيفاتالمدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to stackrox/kube-linter

Open-source alternatives to Kube Linter

30 open-source projects similar to stackrox/kube-linter, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Kube Linter alternative.

  • open-policy-agent/gatekeeperالصورة الرمزية لـ open-policy-agent

    open-policy-agent/gatekeeper

    4,228عرض على GitHub↗

    Gatekeeper is a Kubernetes admission control and policy enforcement engine used to ensure cluster resources comply with organizational security and configuration standards. It intercepts API requests to validate or reject non-compliant resources before they are persisted in the cluster. The project uses a parameterized policy library and custom resource definitions to create reusable templates and enforcement rules. It distinguishes itself through a hub-and-spoke management model, allowing a controller in a management cluster to enforce policies across separate target clusters. Beyond admiss

    Go
    عرض على GitHub↗4,228
  • falcosecurity/falcoالصورة الرمزية لـ falcosecurity

    falcosecurity/falco

    8,670عرض على GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    عرض على GitHub↗8,670
  • cyberark/kubiscanالصورة الرمزية لـ cyberark

    cyberark/KubiScan

    1,428عرض على GitHub↗

    A tool to scan Kubernetes cluster for risky permissions

    Python
    عرض على GitHub↗1,428
  • armosec/kubescapeالصورة الرمزية لـ armosec

    armosec/kubescape

    11,482عرض على GitHub↗

    Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of

    Go
    عرض على GitHub↗11,482

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Find more with AI search
  • controlplaneio/kubesecالصورة الرمزية لـ controlplaneio

    controlplaneio/kubesec

    1,461عرض على GitHub↗

    Security risk analysis for Kubernetes resources

    Go
    عرض على GitHub↗1,461
  • aquasecurity/kube-benchالصورة الرمزية لـ aquasecurity

    aquasecurity/kube-bench

    8,078عرض على GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    عرض على GitHub↗8,078
  • viglesiasce/kube-lintالصورة الرمزية لـ viglesiasce

    viglesiasce/kube-lint

    156عرض على GitHub↗

    A linter for Kubernetes resources with a customizable rule set

    Go
    عرض على GitHub↗156
  • uswitch/klintالصورة الرمزية لـ uswitch

    uswitch/klint

    42عرض على GitHub↗

    A 'realtime' kubernetes resource linter

    Go
    عرض على GitHub↗42
  • appvia/kraneالصورة الرمزية لـ appvia

    appvia/krane

    740عرض على GitHub↗

    Kubernetes RBAC static analysis & visualisation tool

    Ruby
    عرض على GitHub↗740
  • helm/chart-testingالصورة الرمزية لـ helm

    helm/chart-testing

    1,632عرض على GitHub↗

    CLI tool for linting and testing Helm charts

    Go
    عرض على GitHub↗1,632
  • aquasecurity/trivyالصورة الرمزية لـ aquasecurity

    aquasecurity/trivy

    36,462عرض على GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    عرض على GitHub↗36,462
  • snyk-labs/helm-snykالصورة الرمزية لـ snyk-labs

    snyk-labs/helm-snyk

    43عرض على GitHub↗

    Check images in your charts for vulnerabilities

    TypeScript
    عرض على GitHub↗43
  • yannh/kubeconformالصورة الرمزية لـ yannh

    yannh/kubeconform

    3,070عرض على GitHub↗

    A FAST Kubernetes manifests validator, with support for Custom Resources!

    Go
    عرض على GitHub↗3,070
  • dormstern/segspecالصورة الرمزية لـ dormstern

    dormstern/segspec

    15عرض على GitHub↗

    Static analysis from configs → Kubernetes NetworkPolicies in seconds

    Go
    عرض على GitHub↗15
  • kinvolk/inspektor-gadgetالصورة الرمزية لـ kinvolk

    kinvolk/inspektor-gadget

    2,859عرض على GitHub↗

    Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

    C
    عرض على GitHub↗2,859
  • corneliusweig/rakkessالصورة الرمزية لـ corneliusweig

    corneliusweig/rakkess

    1,400عرض على GitHub↗

    Review Access - kubectl plugin to show an access matrix for server resources

    Go
    عرض على GitHub↗1,400
  • aquasecurity/kube-hunterالصورة الرمزية لـ aquasecurity

    aquasecurity/kube-hunter

    5,064عرض على GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Python
    عرض على GitHub↗5,064
  • anchore/grypeالصورة الرمزية لـ anchore

    anchore/grype

    12,423عرض على GitHub↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    Gocontainer-imagecontainerscyclonedx
    عرض على GitHub↗12,423
  • deepfence/threatmapperالصورة الرمزية لـ deepfence

    deepfence/ThreatMapper

    5,282عرض على GitHub↗

    ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

    TypeScriptcloud-nativecloudsecuritycnapp
    عرض على GitHub↗5,282
  • digitalocean/clusterlintالصورة الرمزية لـ digitalocean

    digitalocean/clusterlint

    591عرض على GitHub↗

    A best practices checker for Kubernetes clusters. 🤠

    Go
    عرض على GitHub↗591
  • external-secrets/external-secretsالصورة الرمزية لـ external-secrets

    external-secrets/external-secrets

    6,697عرض على GitHub↗

    External Secrets Operator reads information from a third-party service like AWS Secrets Manager and automatically injects the values as Kubernetes Secrets.

    Goexternal-secretshacktoberfestkubernetes
    عرض على GitHub↗6,697
  • datreeio/datreeالصورة الرمزية لـ datreeio

    datreeio/datree

    6,339عرض على GitHub↗

    Datree is a policy enforcement framework for Kubernetes that validates configurations against rules written in Rego, JSON Schema, or CEL. It operates as both a command-line tool for pre-deployment scanning and as a cluster-side admission webhook for real-time enforcement, integrating with CI/CD pipelines and continuous delivery tools like ArgoCD and FluxCD. The framework supports namespace-scoped policy mapping, allowing different policies to apply to different namespaces, and provides a skip annotation mechanism for selectively bypassing rules on individual resources or entire namespaces. It

    Goadmission-webhookbest-practicescli
    عرض على GitHub↗6,339
  • shopify/kubeauditالصورة الرمزية لـ Shopify

    Shopify/kubeaudit

    1,937عرض على GitHub↗

    kubeaudit helps you audit your Kubernetes clusters against common security controls

    Go
    عرض على GitHub↗1,937
  • kubestellar/consoleالصورة الرمزية لـ kubestellar

    kubestellar/console

    115عرض على GitHub↗

    World's first fully integrated and fully Automated Kubernetes management and orchestration solution

    TypeScript
    عرض على GitHub↗115
  • madhuakula/kubernetes-goatالصورة الرمزية لـ madhuakula

    madhuakula/kubernetes-goat

    5,686عرض على GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    عرض على GitHub↗5,686
  • freelensapp/freelensالصورة الرمزية لـ freelensapp

    freelensapp/freelens

    5,185عرض على GitHub↗

    Freelens is a graphical web dashboard for Kubernetes cluster administration and monitoring. It provides a centralized interface for managing container orchestration environments, featuring a log aggregator for simultaneous multi-pod log viewing, a resource visualizer for mapping system dependencies via force-directed graphs, and a security auditor for reviewing vulnerability reports and certificate expiration dates. The project integrates a generative artificial intelligence operator to automate complex administrative tasks and translate requests into cluster configurations. It further distin

    TypeScriptcloud-nativecontainersdevops
    عرض على GitHub↗5,185
  • cert-manager/trust-managerC

    cert-manager/trust-manager

    0عرض على GitHub↗
    عرض على GitHub↗0
  • cedar-policy/cedarالصورة الرمزية لـ cedar-policy

    cedar-policy/cedar

    1,316عرض على GitHub↗
    Rust
    عرض على GitHub↗1,316
  • caiyeon/goldfishالصورة الرمزية لـ Caiyeon

    Caiyeon/goldfish

    2,127عرض على GitHub↗

    A HashiCorp Vault UI written with VueJS and Vault native Go API

    Vuebulma-cssgogolang
    عرض على GitHub↗2,127
  • aquasecurity/trivy-operatorالصورة الرمزية لـ aquasecurity

    aquasecurity/trivy-operator

    1,890عرض على GitHub↗

    Kubernetes-native security toolkit

    Go
    عرض على GitHub↗1,890