How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
Goss is an infrastructure validation tool and testing framework used to verify that a server's current state matches a desired configuration. It compares live system output against YAML or JSON specifications to validate components such as packages, services, users, and network ports. The tool enables the automated generation of test specifications by capturing the existing state of a system. It supports diverse deployment environments through the use of dynamic templates and variable files. Beyond point-in-time validation, the framework can execute retrying tests that poll for state converg
Safely providing access to a docker daemon to untrusted containers is challenging. By design docker doesn't provide any sort of access control over what can be done over that socket, so anything which has the socket has the same influence over your system as the user that docker is running as.…
This project provides an OCI hook to generate seccomp profiles by tracing the syscalls made by the container. The generated profile would allow all the syscalls made and deny every other syscall.
This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against industry security benchmarks. It functions as a script-based scanner that identifies misconfigurations and vulnerabilities within both the host operating system and container settings. The tool specifically implements the Center for Internet Security standards for Docker to verify host and container configurations. It enables a hardening workflow by comparing system states against these standards to identify security gaps and document compliance status. The audit engine suppor
AppArmor profile generator for docker containers. Basically a better AppArmor profile, than creating one by hand, because who would ever do that.
The main features of jfrazelle/bane are: Container Security Tools.
Projects with overlapping indexed features include: aelsabbahy/goss — Goss is an infrastructure validation tool and testing framework used to verify that a server's current state matches a… buildkite/sockguard — Safely providing access to a docker daemon to untrusted containers is challenging. By design docker doesn't provide… containers/oci-seccomp-bpf-hook — This project provides an OCI hook to generate seccomp profiles by tracing the syscalls made by the container. The… docker/docker-bench-security — This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against… google/docker-explorer — A tool to help forensicate offline docker acquisitions. google/gvisor — This project is a secure container runtime that provides strong isolation for application workloads by implementing a…