awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

21 个仓库

Awesome GitHub RepositoriesContainer Security Scanners

Tools for identifying vulnerabilities, generating software bills of materials, and securing container images.

Distinguishing note: Focuses on security auditing and compliance of container artifacts.

Explore 21 awesome GitHub repositories matching security & cryptography · Container Security Scanners. Refine with filters or upvote what's useful.

Awesome Container Security Scanners GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • aquasecurity/trivyaquasecurity 的头像

    aquasecurity/trivy

    36,462在 GitHub 上查看↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Identifies vulnerabilities and misconfigurations in container images for secure deployment.

    Gocontainersdevsecopsdocker
    在 GitHub 上查看↗36,462
  • veggiemonk/awesome-dockerveggiemonk 的头像

    veggiemonk/awesome-docker

    36,229在 GitHub 上查看↗

    This project is a comprehensive, community-driven directory that serves as a centralized discovery hub for the container ecosystem. It functions as a structured knowledge base, aggregating a wide array of software tools, educational materials, and technical resources designed to assist developers and operators in mastering containerization technologies. The repository distinguishes itself through a meticulously organized taxonomy that maps the entire container lifecycle, from initial development and image building to orchestration, security, and infrastructure operations. By curating disparat

    Provides security scanning and SBOM generation for container images.

    awesomeawesome-listcontainer
    在 GitHub 上查看↗36,229
  • goharbor/harborgoharbor 的头像

    goharbor/harbor

    28,761在 GitHub 上查看↗

    Harbor is a self-hosted, enterprise-grade container registry platform designed to store, sign, and scan container images and cloud-native artifacts. It provides a centralized repository that integrates directly with Kubernetes environments to manage the full lifecycle of software artifacts, from initial storage to production deployment. The platform distinguishes itself through a focus on security, governance, and multi-site availability. It features a pluggable vulnerability scanning framework that allows for the integration of various security engines, alongside content trust mechanisms tha

    Performs automated vulnerability scanning and enforces image integrity through content signing and authenticity verification.

    Gocloud-nativecncfcncf-project
    在 GitHub 上查看↗28,761
  • yeasy/docker_practiceyeasy 的头像

    yeasy/docker_practice

    26,111在 GitHub 上查看↗

    This project is a Docker educational resource and a collection of practical examples designed for learning containerization technologies. It serves as a guide for understanding container fundamentals, including the creation and management of custom images and the use of registries. The repository provides specialized references for container security hardening, such as managing kernel privileges and implementing supply chain security. It also includes tutorials for multi-container orchestration and a DevOps guide focused on CI/CD automation and image optimization. The material covers a broad

    Provides workflows for verifying digital signatures and scanning images for vulnerabilities before deployment.

    Gobookcloud-computingcontainer
    在 GitHub 上查看↗26,111
  • slimtoolkit/slimslimtoolkit 的头像

    slimtoolkit/slim

    22,977在 GitHub 上查看↗

    Slim is a comprehensive suite for container lifecycle management, providing tools for image inspection, optimization, security hardening, and service troubleshooting. It functions as a platform for analyzing containerized applications through both static metadata review and dynamic behavioral probing, enabling users to understand image composition and runtime dependencies. The project distinguishes itself by automating the creation of minimal, production-ready container images. It achieves this by removing unnecessary files and components, flattening image layers, and synthesizing restrictive

    Verifies and signs optimized container images to ensure integrity and authenticity throughout the deployment pipeline.

    Goapparmorcontainersdocker
    在 GitHub 上查看↗22,977
  • voltagent/awesome-claude-code-subagentsVoltAgent 的头像

    VoltAgent/awesome-claude-code-subagents

    21,906在 GitHub 上查看↗

    This project provides a framework for managing multi-agent systems, designed to automate complex software development, infrastructure, and business workflows. It functions as a multi-agent workflow orchestrator that routes tasks to domain-specific workers while maintaining state persistence and infrastructure automation. By leveraging large language models, the system decomposes high-level objectives into actionable plans, ensuring that complex operations are executed with consistency and reliability. The framework distinguishes itself through its hierarchical agent registry and policy-driven

    Analyzes container configurations and registry setups to identify security and performance bottlenecks.

    Shellai-agent-frameworkai-agent-toolsai-agents
    在 GitHub 上查看↗21,906
  • usestrix/strixusestrix 的头像

    usestrix/strix

    20,138在 GitHub 上查看↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Evaluates container images and filesystems for vulnerabilities, configuration errors, and compliance issues.

    Pythonagentsartificial-intelligencecybersecurity
    在 GitHub 上查看↗20,138
  • anchore/grypeanchore 的头像

    anchore/grype

    12,423在 GitHub 上查看↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    Identifies known vulnerabilities in container images to prevent security risks from reaching production environments.

    Gocontainer-imagecontainerscyclonedx
    在 GitHub 上查看↗12,423
  • future-architect/vulsfuture-architect 的头像

    future-architect/vuls

    12,185在 GitHub 上查看↗

    Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit

    Scans running containers and cloud environments to detect outdated software and known security vulnerabilities.

    Go
    在 GitHub 上查看↗12,185
  • hadolint/hadolinthadolint 的头像

    hadolint/hadolint

    12,225在 GitHub 上查看↗

    Hadolint 是一个旨在验证容器构建配置的静态分析工具。它作为一个安全扫描器和配置审计员,将构建指令解析为结构化格式,以识别偏离安全和效率标准的行为。 该工具通过对嵌入式 shell 命令进行深度检查而脱颖而出。通过对这些脚本进行标记化和分析,它能检测到可能残留在容器镜像中的常见脚本错误和安全漏洞。它集成了外部分析工具,为这些内联命令提供专门的验证,确保容器结构和执行逻辑都得到评估。 除了基本的语法检查外,该实用程序还通过识别低效的层创建和不安全的配置设置来支持自动化工作流。它旨在集成到持续集成和部署流水线中,以便在构建镜像之前捕获配置问题。该项目提供了一个用于跨容器定义执行这些审计的命令行界面。

    Validates build configurations to identify security vulnerabilities and inefficient construction patterns.

    Haskelldockerdockerfiledockerfile-linter
    在 GitHub 上查看↗12,225
  • docker-archive-public/docker.labsdocker-archive-public 的头像

    docker-archive-public/docker.labs

    11,904在 GitHub 上查看↗

    This project is a comprehensive collection of tutorials and guided laboratories designed to teach containerization, networking, and security using Docker. It serves as a learning path for building portable images and executing isolated processes. The materials provide specific guides for managing container clusters and scaling services through Docker Swarm and overlay networks. It includes a security handbook for implementing image scanning and secret management, as well as laboratories dedicated to modernizing legacy applications by wrapping older software installers into containers. The co

    Covers vulnerability scanning and image signing to ensure the integrity and security of images within a registry.

    PHPcontainersdockerdocker-compose
    在 GitHub 上查看↗11,904
  • quay/clairquay 的头像

    quay/clair

    11,012在 GitHub 上查看↗

    Clair is a container image vulnerability scanner and security analyzer. It performs static analysis of container images by matching package contents against vulnerability databases to identify security risks across different package formats and architectures. The project functions as both an image indexer and a vulnerability database manager. It processes container layers into intermediate representations to enable fast security lookups and synchronizes security metadata from multiple external sources to maintain a local registry. Capability areas include continuous security monitoring, whic

    Provides comprehensive security analysis and vulnerability scanning for container images.

    Goclaircontainersdocker
    在 GitHub 上查看↗11,012
  • coreos/claircoreos 的头像

    coreos/clair

    11,011在 GitHub 上查看↗

    Clair is a container vulnerability scanner that performs static analysis of container images to identify known security vulnerabilities. It functions as an analyzer for OCI and Docker images, indexing their contents to detect security risks and outdated packages without requiring the containers to be running. The tool identifies vulnerabilities by matching indexed container components against security databases to find common vulnerabilities and exposures. This process involves analyzing filesystem layers to track the provenance and versioning of packages across the image hierarchy. The proj

    Provides a comprehensive container security scanner to identify vulnerabilities and generate software bills of materials.

    Go
    在 GitHub 上查看↗11,011
  • kubernetes/komposekubernetes 的头像

    kubernetes/kompose

    10,542在 GitHub 上查看↗

    Kompose is a suite of conversion utilities designed to translate container composition files into cloud-native cluster resource definitions. It serves as a migration tool that transforms local development specifications into production-ready manifests for Kubernetes and OpenShift. The tool functions as a translation engine that maps container specifications, network settings, and workload definitions into cluster resources. It supports target-specific manifest generation through dedicated providers, allowing for the creation of resources tailored to different environment distributions. The p

    Maps container capability additions and group settings to security contexts within the generated target manifests.

    Go
    在 GitHub 上查看↗10,542
  • docker/docker-bench-securitydocker 的头像

    docker/docker-bench-security

    9,655在 GitHub 上查看↗

    This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against industry security benchmarks. It functions as a script-based scanner that identifies misconfigurations and vulnerabilities within both the host operating system and container settings. The tool specifically implements the Center for Internet Security standards for Docker to verify host and container configurations. It enables a hardening workflow by comparing system states against these standards to identify security gaps and document compliance status. The audit engine suppor

    Scans Docker host settings and container deployments to identify critical security misconfigurations and vulnerabilities.

    Shell
    在 GitHub 上查看↗9,655
  • ko-build/koko-build 的头像

    ko-build/ko

    8,455在 GitHub 上查看↗

    Ko is a daemonless container image builder and OCI image generator specifically for Go applications. It compiles Go source code into binaries and packages them directly into container images, pushing them to registries without requiring a local container runtime or daemon. The tool specializes in multi-platform image distribution, producing images for various CPU architectures and operating systems from a single execution. It distinguishes itself by automating the entire pipeline from Go import paths to Kubernetes deployment or serverless function packaging for architectures like AWS Lambda.

    Generates software bills of materials to track all components and dependencies within a container image.

    Gocontainercontainersdeploy
    在 GitHub 上查看↗8,455
  • anchore/syftanchore 的头像

    anchore/syft

    8,399在 GitHub 上查看↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Acts as a scanner that extracts packages, OS distributions, and binary metadata from OCI and Docker images.

    Gocontainerscyclonedxdocker
    在 GitHub 上查看↗8,399
  • microsoft/security-101microsoft 的头像

    microsoft/Security-101

    6,203在 GitHub 上查看↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    Teaches container security principles including image scanning and runtime isolation.

    HTMLappseccia-triaddata-protection
    在 GitHub 上查看↗6,203
  • kubeflow/pipelineskubeflow 的头像

    kubeflow/pipelines

    4,154在 GitHub 上查看↗

    该项目是一个容器化机器学习工作流引擎和编排器,旨在自动化 Kubernetes 集群上机器学习模型的端到端生命周期。它作为一个 MLOps 管道编译器,将领域特定语言转换为用于便携式和可扩展部署的结构化规范。 该平台提供了一个具有隔离命名空间和身份提供商认证的多租户环境。它通过结合基于容器的任务隔离、用于数据传递的强类型工件管理以及用于避免冗余计算的内容寻址结果缓存而脱颖而出。 该系统涵盖了全面的工作流编排,包括并行任务执行、循环运行调度和条件分支逻辑。它进一步支持实验跟踪、工作流指标收集以及可重用管道组件的管理,并能够为 CPU、内存和 GPU 配置特定的硬件资源请求。 该软件通过 Python SDK 分发,可部署在独立、本地或多租户环境中。

    Translates container capabilities and group settings into cluster-native security contexts for pods.

    Python
    在 GitHub 上查看↗4,154
  • leebaird/discoverleebaird 的头像

    leebaird/discover

    3,892在 GitHub 上查看↗

    Discover 是一个基于 Bash 的渗透测试工具包,旨在自动化侦察、扫描和枚举任务。它是一个综合套件,用于开源情报收集、网络侦察、容器审计、有效载荷生成和安全数据解析。 该项目通过集成多个专业工作流脱颖而出,包括用于提取公司元数据的被动 OSINT 框架、用于映射攻击面的网络侦察套件,以及用于识别镜像和集群中漏洞与密钥的容器安全审计器。它还包含一个 Metasploit 有效载荷生成器,可跨各种架构创建反向 Shell 并自动化配置网络监听器。 该工具包涵盖了广泛的安全操作,包括针对 WAF 和 OAuth 配置错误的 Web 应用漏洞扫描、SSL 证书的基础设施审计,以及将结构化 XML 安全工具输出转换为 CSV 格式。 该工具包专为在 Kali Linux 和 Ubuntu 上运行而设计。

    Audits container images and orchestration clusters for vulnerabilities, leaked secrets, and misconfigurations.

    Shellbashenumerationinformation-gathering
    在 GitHub 上查看↗3,892
上一个12下一个
  1. Home
  2. Security & Cryptography
  3. Container Security Scanners

探索子标签

  • Container Security2 个子标签Vulnerability scanning and image signing for integrity. **Distinct from Container Security Scanners:** Focuses on registry-integrated security features.