Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo
The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and track security vulnerability data across diverse open source software ecosystems. It functions as a unified source of truth for security advisories, providing machine-readable records that help developers and automated tools identify and manage threats within their software supply chains. The platform distinguishes itself by utilizing a version-controlled, git-based storage model that relies on pull-request-driven workflows for community curation and verification. By enforcing a s
Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries. The platform distinguishes itself through its ontology-based normalization and cross-platform entity correlation, which map he
Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc
Scorecard este un scanner de securitate open source și un instrument de analiză a lanțului de aprovizionare software care evaluează postura de securitate a proiectelor prin calcularea metricilor de risc bazate pe bune practici. Funcționează ca un dashboard de sănătate a securității, vizualizând lacunele de securitate prin scoruri și badge-uri pentru a ajuta mentenanții să identifice vulnerabilitățile.
Principalele funcționalități ale ossf/scorecard sunt: Open Source Security Scanners, Security Posture Checklists, Security Auditors, CI/CD Security Metrics Automation, Open Source Security, Security Guides, Repository Security Health Tracking, Remediation Guidance.
Alternativele open-source pentru ossf/scorecard includ: kubescape/kubescape — Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for… github/advisory-database — The advisory database is a centralized repository and intelligence platform designed to aggregate, normalize, and… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… lyft/cartography — Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,…