awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
open-policy-agent avatar

open-policy-agent/conftest

0
View on GitHub↗
3,128 स्टार्स·335 फोर्क्स·Go·other·6 व्यूज़conftest.dev↗

Conftest

Conftest is a suite of tools designed for validating structured configurations, testing policy logic, and generating policy documentation. It serves as a configuration file validator that checks YAML, JSON, and Helm charts for security violations and compliance issues using declarative rules.

The project functions as an Open Policy Agent testing tool, allowing structured configuration files to be validated against custom policies written in Rego. It includes a policy-as-code testing framework to ensure policy logic is correct and a utility to extract metadata from Rego code to create static markdown reference files.

The tool provides capabilities for infrastructure-as-code testing, configuration compliance auditing, and integration into CI/CD pipelines to block non-compliant changes. It supports executing policy validations within containerized environments to maintain consistency across different host operating systems.

Features

  • Policy Evaluation Engines - Provides a policy evaluation engine that checks structured configurations against declarative Rego rules to determine compliance.
  • Policy-Based Validations - Provides declarative policy validation for YAML, JSON, and Helm charts to identify security violations and compliance issues.
  • Configuration Normalization - Converts various configuration formats into a common JSON representation for consistent analysis by the policy engine.
  • Configuration File Validators - Validates the syntax and settings of YAML, JSON, and Helm chart configuration files against declarative rules.
  • Static Configuration Analysis - Performs static analysis of infrastructure-as-code configuration files to identify security risks before deployment.
  • Configuration and Policy Enforcement - Integrates with Open Policy Agent to define and enforce governance and operational standards across structured data.
  • Audit and Compliance - Checks structured system settings against organizational standards to ensure they meet security and operational compliance requirements.
  • Infrastructure as Code Scanners - Analyzes infrastructure-as-code configuration files statically to detect security risks and compliance issues before deployment.
  • Policy-As-Code Engines - Provides a framework to validate infrastructure plans against security and compliance rules using policy-as-code.
  • Policy Validators - Provides tools for checking Rego-based authorization and configuration rules for syntax and logical errors.
  • Policy Logic Testing - Executes test suites against defined policies to ensure rules behave correctly before application to configuration files.
  • Documentation Generators - Extracts structured metadata from policy source code to automatically generate human-readable markdown reference guides.
  • CI/CD Policy Gates - Automates the validation of configuration files within a pipeline to block non-compliant changes from reaching production.
  • Stateless Architectures - Implements a stateless architecture for policy evaluation to ensure reproducible and predictable validation results.
  • Policy Assertion Libraries - Tests configuration files against defined assertions to ensure they adhere to specific security or operational policies.
  • Violation Source Mapping - Associates policy failures with specific line numbers and file paths by extracting coordinates from the parsed configuration.
  • Testing and Troubleshooting - Writes tests against structured configuration data.

स्टार हिस्ट्री

open-policy-agent/conftest के लिए स्टार हिस्ट्री चार्टopen-policy-agent/conftest के लिए स्टार हिस्ट्री चार्ट

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Start searching with AI

Conftest के ओपन-सोर्स विकल्प

समान ओपन-सोर्स प्रोजेक्ट्स, जो Conftest के साथ साझा की गई सुविधाओं के आधार पर रैंक किए गए हैं।
  • kyverno/kyvernokyverno का अवतार

    kyverno/kyverno

    7,841GitHub पर देखें↗

    Kyverno is a Kubernetes policy engine and cloud native governance tool. It functions as a policy-as-code framework that validates, mutates, and generates resources to enforce security and governance standards within a cluster. The project distinguishes itself through a declarative policy model that utilizes native Kubernetes custom resource definitions, allowing policies to be managed as standard cluster objects without custom code. It provides specific security capabilities for container image verification and signature validation to ensure only trusted images are deployed. Its broader capa

    Go
    GitHub पर देखें↗7,841
  • accurics/terrascanaccurics का अवतार

    accurics/terrascan

    5,210GitHub पर देखें↗

    Terrascan is an infrastructure as code security scanner and cloud configuration auditor designed to detect security violations and compliance risks in cloud templates and Dockerfiles before provisioning. It utilizes the Open Policy Agent to evaluate infrastructure templates against both standard security policies and custom organizational rules. The project functions as a security guardrail within build pipelines, blocking risky deployments by integrating scanning logic directly into CI/CD workflows. It also includes a container registry vulnerability scanner that collects vulnerability data

    Go
    GitHub पर देखें↗5,210
  • tenable/terrascantenable का अवतार

    tenable/terrascan

    5,210GitHub पर देखें↗

    Terrascan is a static analysis tool designed to evaluate infrastructure-as-code configuration files for security vulnerabilities and compliance violations. By parsing these files into an intermediate representation, it identifies risks before cloud resources are provisioned, serving as a compliance auditor for cloud-native environments. The tool functions as a policy-as-code engine, allowing users to define and enforce custom security rules and industry benchmarks using a specialized query language. It distinguishes itself through its ability to integrate directly into development and deploym

    Go
    GitHub पर देखें↗5,210
  • tfsec/tfsectfsec का अवतार

    tfsec/tfsec

    7,013GitHub पर देखें↗

    tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect misconfigurations and compliance violations in Terraform and cloud infrastructure definitions before deployment. It functions as a cloud security policy engine that identifies vulnerabilities across multiple cloud platforms. The tool provides capabilities for cloud compliance auditing and scanning of Cloud Development Kit code. It supports custom security policy enforcement and allows for the definition of organization-specific security requirements. The scanner includes features

    Go
    GitHub पर देखें↗7,013
Conftest के सभी 30 विकल्प देखें→

अक्सर पूछे जाने वाले प्रश्न

open-policy-agent/conftest क्या करता है?

Conftest is a suite of tools designed for validating structured configurations, testing policy logic, and generating policy documentation. It serves as a configuration file validator that checks YAML, JSON, and Helm charts for security violations and compliance issues using declarative rules.

open-policy-agent/conftest की मुख्य विशेषताएं क्या हैं?

open-policy-agent/conftest की मुख्य विशेषताएं हैं: Policy Evaluation Engines, Policy-Based Validations, Configuration Normalization, Configuration File Validators, Static Configuration Analysis, Configuration and Policy Enforcement, Audit and Compliance, Infrastructure as Code Scanners।

open-policy-agent/conftest के कुछ ओपन-सोर्स विकल्प क्या हैं?

open-policy-agent/conftest के ओपन-सोर्स विकल्पों में शामिल हैं: kyverno/kyverno — Kyverno is a Kubernetes policy engine and cloud native governance tool. It functions as a policy-as-code framework… accurics/terrascan — Terrascan is an infrastructure as code security scanner and cloud configuration auditor designed to detect security… tenable/terrascan — Terrascan is a static analysis tool designed to evaluate infrastructure-as-code configuration files for security… tfsec/tfsec — tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect… cue-lang/cue — CUE is a constraint-based configuration language designed for data validation, schema definition, and code generation.… cerbos/cerbos — Cerbos is an open-source authorization service that provides a centralized, language-agnostic engine for managing…