awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to spectralops/preflight

Open-source alternatives to Preflight

19 open-source projects similar to spectralops/preflight, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Preflight alternative.

  • anchore/syftanchore avatar

    anchore/syft

    8,399View on GitHub↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Gocontainerscyclonedxdocker
    View on GitHub↗8,399
  • aquasecurity/chain-benchaquasecurity avatar

    aquasecurity/chain-bench

    774View on GitHub↗

    An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

    Go
    View on GitHub↗774
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    View on GitHub↗36,462

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
baalmor/cve-apebaalmor avatar

baalmor/cve-ape

5View on GitHub↗

A CVE scanner which can process a pkglist.

Python
View on GitHub↗5
  • deislabs/ratifydeislabs avatar

    deislabs/ratify

    303View on GitHub↗

    Artifact Ratification Framework (CNCF Sandbox)

    Go
    View on GitHub↗303
  • denysvuika/supply-chain-inspectorDenysVuika avatar

    DenysVuika/supply-chain-inspector

    3View on GitHub↗

    A standalone, zero-dependency Node.js script for supply chain security analysis of npm dependencies.

    JavaScript
    View on GitHub↗3
  • dev-sec/ansible-os-hardeningdev-sec avatar

    dev-sec/ansible-os-hardening

    5,391View on GitHub↗

    This project is a collection of automated hardening frameworks and Ansible roles designed to secure Linux systems, databases, SSH services, and web servers. It functions as a configuration framework that reduces the attack surface of Linux distributions through the automated enforcement of security policies. The collection provides specific security baselines for a variety of services, including MySQL databases, OpenSSH daemons, and web servers such as Nginx and Apache. These roles are designed to remove insecure defaults, enforce secure authentication methods, and align system configurations

    Jinja
    View on GitHub↗5,391
  • en/code-securityE

    en/code-security

    0View on GitHub↗
    View on GitHub↗0
  • grafeas/kritisgrafeas avatar

    grafeas/kritis

    710View on GitHub↗

    Deploy-time Policy Enforcer for Kubernetes applications

    Go
    View on GitHub↗710
  • in-toto/attestationin-toto avatar

    in-toto/attestation

    341View on GitHub↗

    in-toto Attestation Framework

    Rust
    View on GitHub↗341
  • os-scar/overlayos-scar avatar

    os-scar/overlay

    228View on GitHub↗

    Overlay

    JavaScript
    View on GitHub↗228
  • selefra/selefraselefra avatar

    selefra/selefra

    545View on GitHub↗

    The open-source policy-as-code software that provides analysis for Multi-Cloud and SaaS environments, you can get insight with natural language (powered by OpenAI).

    Goawsazurechatgpt
    View on GitHub↗545
  • sigstore/cosignsigstore avatar

    sigstore/cosign

    5,667View on GitHub↗

    Cosign is a tool for signing and verifying software artifacts, primarily those stored in OCI-compatible registries such as container images, Helm charts, SBOMs, and Tekton bundles. It supports keyless signing using ephemeral keys and short-lived certificates from the Sigstore public-good infrastructure, associating signatures with an OpenID Connect identity rather than a long-lived cryptographic key. The project provides multiple signing and verification methods, including private keys, key pairs stored in KMS providers like AWS KMS and Azure Key Vault, and hardware security keys. It can sign

    Go
    View on GitHub↗5,667
  • sigstore/fulciosigstore avatar

    sigstore/fulcio

    859View on GitHub↗

    Sigstore OIDC PKI

    Go
    View on GitHub↗859
  • sigstore/rekorsigstore avatar

    sigstore/rekor

    1,168View on GitHub↗

    Software Supply Chain Transparency Log

    Go
    View on GitHub↗1,168
  • slsa-framework/slsaslsa-framework avatar

    slsa-framework/slsa

    1,881View on GitHub↗

    Supply-chain Levels for Software Artifacts

    HTML
    View on GitHub↗1,881
  • spectralops/tellerspectralops avatar

    spectralops/teller

    3,215View on GitHub↗

    Cloud native secrets management for developers - never leave your command line for secrets.

    Rust
    View on GitHub↗3,215
  • step-security/harden-runnerstep-security avatar

    step-security/harden-runner

    1,206View on GitHub↗

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

    TypeScript
    View on GitHub↗1,206
  • tektoncd/chainstektoncd avatar

    tektoncd/chains

    271View on GitHub↗

    Supply Chain Security in Tekton Pipelines

    Go
    View on GitHub↗271