awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

18 Repos

Awesome GitHub RepositoriesRisk Mitigation

Tools for identifying project issues and executing contingency plans.

Distinct from Project Planning: Focuses on proactive risk mitigation and contingency planning, distinct from high-level project planning.

Explore 18 awesome GitHub repositories matching software engineering & architecture · Risk Mitigation. Refine with filters or upvote what's useful.

Awesome Risk Mitigation GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • voltagent/awesome-claude-code-subagentsAvatar von VoltAgent

    VoltAgent/awesome-claude-code-subagents

    21,906Auf GitHub ansehen↗

    This project provides a framework for managing multi-agent systems, designed to automate complex software development, infrastructure, and business workflows. It functions as a multi-agent workflow orchestrator that routes tasks to domain-specific workers while maintaining state persistence and infrastructure automation. By leveraging large language models, the system decomposes high-level objectives into actionable plans, ensuring that complex operations are executed with consistency and reliability. The framework distinguishes itself through its hierarchical agent registry and policy-driven

    Identifies project issues and executes contingency plans for risk mitigation.

    Shellai-agent-frameworkai-agent-toolsai-agents
    Auf GitHub ansehen↗21,906
  • fallibleinc/security-guide-for-developersAvatar von FallibleInc

    FallibleInc/security-guide-for-developers

    21,090Auf GitHub ansehen↗

    This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which

    Uses frequency and impact statistics of common vulnerabilities to determine the most urgent mitigation efforts.

    Auf GitHub ansehen↗21,090
  • easychen/lean-side-bussinessAvatar von easychen

    easychen/lean-side-bussiness

    11,984Auf GitHub ansehen↗

    This project is a comprehensive software entrepreneurship curriculum and solopreneurship business playbook designed for developers. It provides a strategic framework for building, validating, and monetizing side businesses using lean startup methodology and a systematic product development approach. The project distinguishes itself by offering specific guides for digital monetization and career anti-fragility, helping software engineers transition from employment to self-employment. It focuses on turning technical skills into scalable digital assets, paid communities, and independent software

    Implements a strategy using minimum viable products to test market demand and reduce feature development risk.

    Auf GitHub ansehen↗11,984
  • bloodhoundad/bloodhoundAvatar von BloodHoundAD

    BloodHoundAD/BloodHound

    10,552Auf GitHub ansehen↗

    BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within Active Directory environments. It functions as an attack path mapper and risk assessment system that uses graph theory to identify hidden relationships and paths leading to high-privilege accounts. The tool specializes in network attack surface mapping and privilege escalation pathfinding. It quantifies security risks by measuring the reliability of attack paths to critical targets, allowing for the prioritization of vulnerability elimination. The system provides capabilities for

    Measures the reliability of attack paths to prioritize the elimination of critical security vulnerabilities.

    PowerShell
    Auf GitHub ansehen↗10,552
  • six2dez/reconftwAvatar von six2dez

    six2dez/reconftw

    7,226Auf GitHub ansehen↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Ranks security flaws based on impact and frequency to generate a risk-scored list for prioritized remediation.

    Shellbug-bountybugbountybugbounty-tool
    Auf GitHub ansehen↗7,226
  • microsoft/security-101Avatar von microsoft

    microsoft/Security-101

    6,203Auf GitHub ansehen↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    Teaches the full lifecycle of identifying, assessing, prioritizing, mitigating, and monitoring vulnerabilities.

    HTMLappseccia-triaddata-protection
    Auf GitHub ansehen↗6,203
  • projectdiscovery/naabuAvatar von projectdiscovery

    projectdiscovery/naabu

    5,766Auf GitHub ansehen↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Ranks vulnerabilities based on attacker techniques to prioritize the most critical weaknesses.

    Gocdn-exclusionhacktoberfestnmap
    Auf GitHub ansehen↗5,766
  • snyk/snykAvatar von snyk

    snyk/snyk

    5,586Auf GitHub ansehen↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    Ranks identified flaws based on risk scores and severity levels to focus remediation efforts on the most critical threats.

    TypeScript
    Auf GitHub ansehen↗5,586
  • snyk/cliAvatar von snyk

    snyk/cli

    5,428Auf GitHub ansehen↗

    The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies, proprietary application code, container images, and infrastructure-as-code configuration files. It also serves as a platform management tool, allowing users to configure organizations, users, SSO, and reporting from the terminal rather than the web dashboard. The CLI integrates directly into development workflows, enabling scanning within IDEs, build pipelines, and version control systems. It implements static analysis with interfile data flow analysis to find complex security f

    Prioritizes vulnerabilities using risk scores, severity, and exploit maturity to focus remediation.

    TypeScriptmonitorsecuritysnyk
    Auf GitHub ansehen↗5,428
  • owasp/top10Avatar von OWASP

    OWASP/Top10

    5,273Auf GitHub ansehen↗

    This project is a web application security standard and vulnerability framework. It provides a comprehensive list of the most critical security risks facing web applications, paired with technical guidance and a structured methodology for identifying and mitigating these flaws. The framework functions as a secure coding guide and a risk assessment methodology, offering a standardized approach to prioritizing vulnerabilities based on their potential impact and likelihood of exploitation. It defines architectural patterns and technical recommendations to help developers implement defense in dep

    Provides a standardized methodology for ranking security flaws based on impact and frequency to prioritize mitigation.

    HTML
    Auf GitHub ansehen↗5,273
  • tlbootcamp/tlroadmapAvatar von tlbootcamp

    tlbootcamp/tlroadmap

    5,131Auf GitHub ansehen↗

    tlroadmap ist ein Engineering-Leadership-Roadmap- und Management-Curriculum, das den Übergang vom technischen Mitarbeiter zur Führungskraft begleiten soll. Es bietet eine strukturierte Zusammenstellung von Kompetenzen und eine Wissensdatenbank für technisches Management mit Fokus auf organisatorische Ausrichtung, Personalmanagement und operative Exzellenz. Das Projekt konzentriert sich auf eine Kompetenzlandkarte für Teamleiter und Frameworks für die berufliche Entwicklung. Es skizziert die Hard- und Soft-Skills, die für das Management von Entwicklern und Produktstrategien erforderlich sind, einschließlich der Erstellung individueller Wachstumspläne und der Bewertung von Führungskompetenzen. Die Ressource deckt ein breites Spektrum an Management-Fähigkeiten ab, einschließlich Talentakquise und Optimierung des Recruiting-Funnels, Management des Mitarbeiter-Lebenszyklus vom Onboarding bis zum Austritt sowie das Design operativer Workflows. Es adressiert zudem Produktmanagement durch Roadmap-Erstellung und Backlog-Priorisierung sowie Organisationsdesign und die Ausrichtung der Unternehmenskultur. Das Projekt ist als Vue-Anwendung implementiert.

    Provides a process for mitigating operational risks during departures by redistributing workloads.

    Vuehacktoberfestmanagementroadmap
    Auf GitHub ansehen↗5,131
  • hahwul/dalfoxAvatar von hahwul

    hahwul/dalfox

    4,846Auf GitHub ansehen↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    Ranks discovered vulnerabilities based on verification levels to highlight high-impact results.

    Gobugbountybugbounty-toolcicd-pipeline
    Auf GitHub ansehen↗4,846
  • intuitem/ciso-assistant-communityAvatar von intuitem

    intuitem/ciso-assistant-community

    4,162Auf GitHub ansehen↗

    This project is a governance, risk, and compliance platform designed to centralize security governance, risk management, and regulatory compliance activities. It functions as a cybersecurity framework manager and a quantitative risk management system, allowing organizations to track their security posture through a centralized hub. The platform is distinguished by its ability to decouple regulatory requirements from technical security controls, enabling users to map a single implementation across multiple global frameworks to reduce audit duplication. It further differentiates itself through

    Assigns specific security controls to mitigate identified risks and calculate residual risk across frameworks.

    Pythonauditautomationbsi
    Auf GitHub ansehen↗4,162
  • sjqzhang/go-fastdfsAvatar von sjqzhang

    sjqzhang/go-fastdfs

    4,138Auf GitHub ansehen↗

    go-fastdfs is a distributed file system and object storage server designed for building private cloud storage. It provides a FastDFS compatible storage implementation that manages clusters of storage nodes to handle large-scale file uploads and downloads. The system focuses on high availability through a decentralized architecture that automatically synchronizes data and repairs failures across multiple machines without a central coordinator. It specifically supports resumable file storage via HTTP, allowing large transfers to be paused and resumed from the last successful byte to handle netw

    Identifies bottlenecks and iteration risks to provide early warning notifications to stakeholders.

    Gobreakpoint-resumecloud-storagecloudnative
    Auf GitHub ansehen↗4,138
  • eon01/dockercheatsheetAvatar von eon01

    eon01/DockerCheatSheet

    3,938Auf GitHub ansehen↗

    Dieses Projekt ist ein umfassendes Referenzhandbuch und Cheat Sheet für die Docker CLI. Es bietet eine strukturierte Sammlung von Befehlen und Dokumentationen, die Benutzern helfen, Container-Lebenszyklen zu verwalten, Images zu bauen und Registries zu handhaben. Die Dokumentation behandelt speziell die Orchestrierung von Multi-Container-Anwendungen mittels Docker Compose und die Verwaltung skalierbarer Services über mehrere Knoten hinweg mittels Docker Swarm. Sie enthält zudem detaillierte Anleitungen zur Konfiguration virtueller Netzwerke, Bridges und Ports, um die Container-Kommunikation zu steuern. Der Referenzumfang erstreckt sich auf die Verwaltung von Container-Images, einschließlich Tagging und Distribution, sowie die Ressourcenwartung zur Rückgewinnung von Speicherplatz durch das Bereinigen ungenutzter Volumes und verwaister Images. Zudem bietet sie Anleitungen zur Inspektion von Container-Metadaten und zur Performance-Überwachung. Die Inhalte werden als eine Reihe von Markdown-basierten technischen Dokumenten bereitgestellt, die als statische Dateien in einem versionskontrollierten Repository gehostet werden.

    Provides a reference for ranking and prioritizing security flaws for mitigation.

    Auf GitHub ansehen↗3,938
  • dependencytrack/dependency-trackAvatar von DependencyTrack

    DependencyTrack/dependency-track

    3,612Auf GitHub ansehen↗

    Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity

    Prioritizes vulnerability mitigation by combining security data with exploit prediction scores to identify urgent risks.

    Javaappsecbill-of-materialsbom
    Auf GitHub ansehen↗3,612
  • parcadei/continuous-claude-v3Avatar von parcadei

    parcadei/Continuous-Claude-v3

    3,531Auf GitHub ansehen↗

    This project is an agentic development framework and autonomous software engineering system. It utilizes a coordinated network of specialized LLM agents to automate the full software development lifecycle, from codebase exploration and architectural planning to implementation and automated refactoring. The system is distinguished by an agentic memory system and a test-driven development orchestrator. It maintains project continuity across sessions by capturing architectural learnings and state in a persistent semantic database and enforces code quality through an automated cycle of generating

    Conducts premortem evaluations to identify and mitigate potential failure points before implementing technical changes.

    Pythonagentsclaude-codeclaude-code-cli
    Auf GitHub ansehen↗3,531
  • flipkart-incubator/astraAvatar von flipkart-incubator

    flipkart-incubator/Astra

    2,639Auf GitHub ansehen↗

    Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints

    Provides automated mapping of scan results against security patterns to categorize and prioritize API weaknesses.

    Pythonci-cdowasppenetration-testing
    Auf GitHub ansehen↗2,639
  1. Home
  2. Software Engineering & Architecture
  3. Project Planning
  4. Risk Mitigation

Unter-Tags erkunden

  • Hierarchical Risk SummariesSummarization of vulnerabilities and policy violations from nested child projects to parent projects. **Distinct from Risk Mitigation:** Specifically handles the aggregation of security findings through project hierarchies.
  • Market-DrivenUsing minimum viable products and market testing to reduce the risk of developing unwanted features. **Distinct from Risk Mitigation:** Focuses on reducing commercial/market risk via MVPs, rather than technical project issue tracking.
  • Security Control MappingThe process of assigning specific security controls to mitigate identified risks and calculate residual risk. **Distinct from Risk Mitigation:** Distinct from generic project risk mitigation by focusing on the application of technical and administrative security controls.
  • Staff Transition PlanningContingency planning for personnel departures, focusing on workload redistribution and knowledge transfer. **Distinct from Risk Mitigation:** Distinct from general project risk mitigation: specifically focuses on the human resource risk of employees leaving the team.
  • Vulnerability Prioritization2 Sub-TagsMethods for ranking security flaws based on impact and frequency to determine mitigation priority. **Distinct from Risk Mitigation:** Distinct from general Risk Mitigation by focusing specifically on the statistical prioritization of known software vulnerabilities.