awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

141 个仓库

Awesome GitHub RepositoriesVulnerability Scanning

Tools for identifying and managing security vulnerabilities in container images.

Distinguishing note: Focuses on proactive vulnerability analysis.

Explore 141 awesome GitHub repositories matching security & cryptography · Vulnerability Scanning. Refine with filters or upvote what's useful.

Awesome Vulnerability Scanning GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • affaan-m/eccaffaan-m 的头像

    affaan-m/ECC

    221,981在 GitHub 上查看↗

    ECC 是一个 LLM 智能体编排框架和跨平台 AI 工具套件,旨在协调多模型工作流。它提供了一个用于管理专业智能体角色、可复用技能和结构化规划的系统,以在不同的 AI 驱动代码编辑器中执行复杂的软件开发任务。 该项目作为模型上下文协议(Model Context Protocol)管理器脱颖而出,提供了一个配置层来集成外部服务器并审计工具执行。它进一步实现了一个智能体安全沙箱,限制敏感文件访问并扫描密钥泄露,以保护自主工作流。 该框架涵盖了广泛的能力领域,包括带有测试驱动开发护栏的 AI 编码工作流自动化、通过智能路由实现模型成本优化以及状态隔离的内存管理。它还包括用于强制执行特定语言编码标准和管理跨各种集成开发环境的智能体行为的工具。 该系统通过命令行界面进行管理,该界面处理工具安装、配置修复和工具预设的部署。

    Scans configurations for vulnerabilities and injection risks using static analysis and deep scanning.

    JavaScript
    在 GitHub 上查看↗221,981
  • moby/mobymoby 的头像

    moby/moby

    71,729在 GitHub 上查看↗

    Moby is an OCI container engine and runtime manager designed for building, running, and managing isolated containers based on Open Container Initiative standards. It functions as a container daemon and image builder, providing a core engine to orchestrate the full lifecycle of containers and the packaging of source code into portable images. The project provides a standardized HTTP interface that allows for programmatic container management, enabling external clients to control daemon settings and container operations. It supports a rootless security model, allowing the engine daemon to execu

    Includes capabilities to scan images and codebases for known security vulnerabilities.

    Gocontainersdockergo
    在 GitHub 上查看↗71,729
  • keygraphhq/shannonKeygraphHQ 的头像

    KeygraphHQ/shannon

    44,672在 GitHub 上查看↗

    Shannon is an integrated security platform designed for autonomous penetration testing, static and dynamic analysis, and automated vulnerability remediation within self-hosted, private infrastructure. It functions as a unified security suite that orchestrates the entire lifecycle of vulnerability management, from initial discovery and reachability prioritization to the generation and verification of code-level patches. The platform distinguishes itself through its agentic approach to security, deploying autonomous agents to execute both black-box and white-box exploits against running applica

    Adjusts vulnerability severity scores based on execution path analysis to focus remediation on confirmed threats.

    TypeScriptpenetration-testingpentestingsecurity-audit
    在 GitHub 上查看↗44,672
  • docker/composedocker 的头像

    docker/compose

    37,588在 GitHub 上查看↗

    Docker Compose is a tool for defining and running multi-container applications through declarative configuration files. It functions as an application lifecycle manager, coordinating the startup, shutdown, and scaling of interconnected services within isolated environments. By using a standardized configuration format, it enables infrastructure as code, allowing developers to manage complex application stacks and their dependencies in a single, repeatable file. The project distinguishes itself by integrating directly with the broader Docker platform, leveraging a client-server architecture wh

    Provides proactive vulnerability scanning for container images.

    Godockerdocker-composego
    在 GitHub 上查看↗37,588
  • github/awesome-copilotgithub 的头像

    github/awesome-copilot

    35,119在 GitHub 上查看↗

    Awesome Copilot is a comprehensive framework for autonomous software development, providing the infrastructure to orchestrate multi-agent teams and automate complex coding workflows. It functions as a centralized platform for managing AI-driven development, enabling developers to deploy specialized agents that interact with local files, terminal commands, and external APIs to execute end-to-end software delivery tasks. The project distinguishes itself through its focus on governance and extensibility, offering a suite of security controls, policy-based execution guardrails, and audit trails t

    Inspects modified files and dependencies for leaked credentials and security vulnerabilities.

    Pythonaigithub-copilothacktoberfest
    在 GitHub 上查看↗35,119
  • projectdiscovery/nucleiprojectdiscovery 的头像

    projectdiscovery/nuclei

    29,189在 GitHub 上查看↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Executes automated security checks against web applications and network infrastructure to identify vulnerabilities.

    Goattack-surfacecve-scannerdast
    在 GitHub 上查看↗29,189
  • goharbor/harborgoharbor 的头像

    goharbor/harbor

    28,761在 GitHub 上查看↗

    Harbor is a self-hosted, enterprise-grade container registry platform designed to store, sign, and scan container images and cloud-native artifacts. It provides a centralized repository that integrates directly with Kubernetes environments to manage the full lifecycle of software artifacts, from initial storage to production deployment. The platform distinguishes itself through a focus on security, governance, and multi-site availability. It features a pluggable vulnerability scanning framework that allows for the integration of various security engines, alongside content trust mechanisms tha

    Integrates modular security engines to perform automated vulnerability scanning on container images.

    Gocloud-nativecncfcncf-project
    在 GitHub 上查看↗28,761
  • goldbergyoni/javascript-testing-best-practicesgoldbergyoni 的头像

    goldbergyoni/javascript-testing-best-practices

    24,589在 GitHub 上查看↗

    This project is a comprehensive knowledge base and educational resource for JavaScript developers, focused on establishing industry-standard methodologies for automated software testing. It provides a structured collection of design patterns and actionable guidelines designed to improve code reliability, maintainability, and overall software quality across the development lifecycle. The repository distinguishes itself by offering a granular, pattern-based approach to testing that spans unit, integration, and end-to-end verification. It emphasizes specific architectural strategies such as comp

    Advocates for continuous monitoring of dependencies to detect and address security vulnerabilities.

    JavaScriptangularchaici
    在 GitHub 上查看↗24,589
  • usestrix/strixusestrix 的头像

    usestrix/strix

    20,138在 GitHub 上查看↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Automates security analysis by orchestrating language model checks within isolated environments for comprehensive penetration audits.

    Pythonagentsartificial-intelligencecybersecurity
    在 GitHub 上查看↗20,138
  • rustscan/rustscanRustScan 的头像

    RustScan/RustScan

    19,932在 GitHub 上查看↗

    RustScan is a high-speed TCP network scanner written in Rust, designed for security reconnaissance and network mapping. It functions as an automated port discovery engine that identifies open ports on remote hosts using IPv6 addresses, CIDR ranges, or bulk input files. The tool is built for rapid surface area discovery, utilizing parallel port processing and OS-aware performance optimizations to identify active services. It allows for scan precision tuning through adjustable connection timeout thresholds and concurrent request controls to balance speed and accuracy. The system integrates wit

    Supports automatically triggering external scripts to handle results or alerts after a scanning process.

    Rust
    在 GitHub 上查看↗19,932
  • dyad-sh/dyaddyad-sh 的头像

    dyad-sh/dyad

    19,648在 GitHub 上查看↗

    Dyad is a local, artificial intelligence-powered development environment designed to manage, edit, and scaffold full-stack software projects. It functions as an automated codebase manager and code editor that leverages language models to execute programming tasks, maintain project context, and apply targeted modifications directly to source files on a user's machine. The platform distinguishes itself through a model-agnostic architecture that allows for flexible integration with various language model runtimes. It provides specialized operational modes to optimize development speed and effici

    Scans source code using artificial intelligence to identify and categorize security risks by severity level.

    TypeScriptai-app-builderanthropicartificial-intelligence
    在 GitHub 上查看↗19,648
  • agent0ai/agent-zeroagent0ai 的头像

    agent0ai/agent-zero

    18,103在 GitHub 上查看↗

    Agent Zero is an autonomous AI agent framework designed to execute complex, multi-step workflows by managing its own environment, persistent memory, and external tool interactions. It functions as a Python-based automation library that enables agents to write code, execute terminal commands, and perform system-level tasks independently. The system is built to handle large-scale operations through hierarchical agent delegation, allowing for the coordination of subordinate agents to maintain focus and context. The platform distinguishes itself through a focus on secure, isolated execution and s

    Automatically scans external tools and community plugins for vulnerabilities before they are deployed to the agent environment.

    Pythonagentaiassistant
    在 GitHub 上查看↗18,103
  • piskvorky/gensimpiskvorky 的头像

    piskvorky/gensim

    16,361在 GitHub 上查看↗

    Gensim is a natural language processing toolkit designed for large-scale text analysis and the training of semantic vector embeddings. It provides a framework for identifying latent thematic structures within document collections and calculating semantic similarity between text segments using unsupervised statistical algorithms. The project is distinguished by its ability to handle datasets that exceed available system memory through incremental corpus streaming, which processes documents one at a time from disk. It utilizes sparse vector representations and dictionary-based token mapping to

    Scans storage to identify sensitive information without moving data off the network.

    Pythondata-miningdata-sciencedocument-similarity
    在 GitHub 上查看↗16,361
  • carpedm20/awesome-hackingcarpedm20 的头像

    carpedm20/awesome-hacking

    15,722在 GitHub 上查看↗

    This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational materials. It functions as a centralized index for researchers and students to discover frameworks and utilities across the entire security lifecycle, ranging from initial vulnerability assessment to post-exploitation analysis. The repository distinguishes itself through a hierarchical taxonomy that organizes diverse security disciplines into a searchable, version-controlled knowledge base. Rather than hosting software directly, it utilizes a decentralized aggregation model that lin

    Includes resources for automated vulnerability scanning to detect software weaknesses.

    awesomehacking
    在 GitHub 上查看↗15,722
  • zaproxy/zaproxyzaproxy 的头像

    zaproxy/zaproxy

    15,293在 GitHub 上查看↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Implements an active scanning engine that sends malicious payloads to identify web vulnerabilities.

    Java
    在 GitHub 上查看↗15,293
  • ultimatehackers/xsstrikeUltimateHackers 的头像

    UltimateHackers/XSStrike

    15,027在 GitHub 上查看↗

    XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.

    Matches JavaScript library version strings against a database of known vulnerable releases.

    Python
    在 GitHub 上查看↗15,027
  • sundowndev/hacker-roadmapsundowndev 的头像

    sundowndev/hacker-roadmap

    15,081在 GitHub 上查看↗

    Hacker Roadmap is a community-driven repository that functions as a structured learning path and resource directory for cybersecurity and ethical hacking. It organizes complex security concepts into sequential modules, guiding users from fundamental knowledge to advanced technical exploitation skills through a curated collection of educational materials and professional development resources. The project distinguishes itself by acting as a centralized index that maps specialized third-party security software and isolated training environments to specific operational use cases. By aggregating

    Aggregates technical advisories and research to support professional development and threat analysis.

    exploitationframeworkshacking
    在 GitHub 上查看↗15,081
  • wazuh/wazuhwazuh 的头像

    wazuh/wazuh

    14,779在 GitHub 上查看↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Scans systems and applications for known security weaknesses and missing updates to ensure a hardened infrastructure.

    Ccloud-securitycomplianceconfiguration-assessement
    在 GitHub 上查看↗14,779
  • maurosoria/dirsearchmaurosoria 的头像

    maurosoria/dirsearch

    14,403在 GitHub 上查看↗

    dirsearch is a command-line security tool and web path scanner used for discovering hidden directories and files on web servers. It functions as a recursive directory fuzzer and brute-force utility that identifies undocumented paths and sensitive files using wordlists and HTTP status codes. The tool distinguishes itself through template-driven path generation and an automated HTTP response filter that uses status codes, content length, and regex patterns to isolate valid targets. It supports recursive directory crawling to map complex web structures and provides state-persistence serializatio

    Provides programmatic interfaces to trigger automated security scans within larger discovery workflows.

    Python
    在 GitHub 上查看↗14,403
  • analysis-tools-dev/static-analysisanalysis-tools-dev 的头像

    analysis-tools-dev/static-analysis

    14,389在 GitHub 上查看↗

    This project is a comprehensive, curated directory of static analysis, linting, and security scanning utilities. It serves as a central resource for developers to discover, compare, and select tools based on specific programming languages, licensing models, and integration requirements. The directory distinguishes itself by providing deep metadata for each listed utility, including community-driven popularity rankings, maintenance status, and deployment methods. By aggregating these tools into a single searchable index, it enables teams to identify solutions for enforcing coding standards, ma

    Scans dependencies and binaries for known security flaws and unsafe code patterns to ensure application integrity.

    Rustanalysisawesome-listcode-quality
    在 GitHub 上查看↗14,389
上一个123456…8下一个
  1. Home
  2. Security & Cryptography
  3. Vulnerability Scanning

探索子标签

  • Black Box ScanningVulnerability detection performed by analyzing public interfaces and HTTP responses without internal system access. **Distinct from Vulnerability Scanning:** Focuses on external-facing probes and response signatures rather than container image or source code analysis
  • CI Pipeline IntegrationAutomated vulnerability scanning integrated into the continuous integration build process. **Distinct from Vulnerability Scanning:** Focuses on the automation of scanning within a pipeline rather than the act of scanning an image in isolation.
  • Container Image Vulnerability Scanners3 个子标签Tools that inspect container images and Kubernetes manifests for known OS and application-layer vulnerabilities. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: focuses specifically on container images and Kubernetes manifests, not general application or network scanning.
  • JavaScript LibrariesVulnerability scanning specifically targeting JavaScript libraries and modules. **Distinct from Vulnerability Scanning:** Specializes in JavaScript library version detection rather than general container or source code vulnerability scanning
  • LLM Security ScanningAnalysis of LLM configurations and prompt-response patterns to detect security vulnerabilities and attack vectors. **Distinct from Vulnerability Scanning:** Focuses on prompt-based attack vectors and LLM-specific constraints rather than container image vulnerabilities.
  • Offline Vulnerability AnalysisPerforming vulnerability lookups using local databases in air-gapped environments without internet access. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: specifically targets the offline/air-gapped capability rather than general scanning.
  • Pattern-Based Detection2 个子标签Using signature-based matching to identify specific vulnerabilities or software patterns across assets. **Distinct from Vulnerability Scanning:** Focuses on YARA-style pattern matching across discovered assets rather than general image or package scanning
  • Platform EnumerationDetection of specific hardware or runtime environments to identify applicable vulnerabilities. **Distinct from Vulnerability Scanning:** Focuses on identifying the target platform first to narrow down potential vulnerabilities, rather than generic scanning.
  • Plugin ScannersAutomated tools for validating external plugins and scripts for security vulnerabilities before execution. **Distinct from Vulnerability Scanning:** Distinct from general vulnerability scanning: focuses specifically on the pre-deployment validation of agent plugins.
  • RAG Pipeline ScanningSpecialized vulnerability scanning for retrieval-augmented generation systems, focusing on indirect prompt injection. **Distinct from Vulnerability Scanning:** Specifically targets the retrieval-augmented generation flow rather than generic containers or network assets.
  • Reachability PrioritizersTools that adjust vulnerability severity based on execution path analysis to focus on confirmed threats. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: focuses on path-based prioritization of existing findings rather than initial discovery.
  • Research IntelligenceIntegrates real-time web research into vulnerability analysis workflows. **Distinct from Vulnerability Scanning:** Distinct from general vulnerability scanning: focuses on real-time external research integration.
  • Scan Contextualization1 个子标签Provides credentials and focus areas to tailor vulnerability research. **Distinct from Vulnerability Scanning:** Distinct from general vulnerability scanning: focuses on user-provided guidance and context.
  • Scan Coordination & Reporting1 个子标签Management of authentication, scheduling, and the aggregation of vulnerability data into reports. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning by focusing on the orchestration and output phase rather than the detection process
  • Scanning Template Libraries3 个子标签Collections of structured configurations for identifying security vulnerabilities across web and network services. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: focuses on the library of reusable templates rather than the scanning engine.
  • Sensitive Data Scanners1 个子标签Automated tools for detecting credentials and vulnerabilities in source code. **Distinct from Vulnerability Scanning:** Distinct from general vulnerability scanning: focuses specifically on credential and sensitive data leakage detection.
  • Severity-Grouped ReviewsReview scan results grouped by severity and provide actions to fix identified issues. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: focuses on reviewing results grouped by severity, not the scanning process itself.
  • Static Analysis Security TestingTools that analyze source code without executing it to find security vulnerabilities. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: specifically focuses on source code analysis (SAST) rather than container image or runtime scanning.
  • Vulnerability Aggregator Synchronizers1 个子标签Tools that synchronize security findings and event notifications with external vulnerability aggregation platforms. **Distinct from Vulnerability Data Synchronization:** Focuses on outbound synchronization to aggregators rather than inbound updates from vulnerability sources.
  • Vulnerability Check Definitions2 个子标签Structured configurations for specifying network requests and validation logic to identify security flaws. **Distinct from Vulnerability Scanning:** Distinct from general vulnerability scanning: focuses on the definition of custom check logic rather than the scanning tool itself.
  • Vulnerability Data AggregatorsSystems that collect and serve security information from multiple sources following a standardized format. **Distinct from Vulnerability Data Synchronization:** Distinct from synchronization: focuses on the aggregation and serving of data rather than just the transport mechanism.
  • Vulnerability Data ProvisioningThe process of populating a scanning system with necessary security tests and compliance policies. **Distinct from Vulnerability Data Synchronization:** Distinct from synchronization as it refers to the initial or bulk population of data via loading services.
  • Vulnerability Data Synchronization1 个子标签Mechanisms for updating local security definitions from remote vulnerability sources. **Distinct from Vulnerability Scanning:** Focuses on the synchronization of vulnerability data rather than the act of scanning images or code.
  • Vulnerability DeletersRemoves a batch of scan vulnerabilities by their IDs, type, status, severity, host, template, or search criteria. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: focuses on deleting existing vulnerability records, not the scanning process itself.
  • Vulnerability Export APIsExport a specific scan vulnerability in JSON or CSV format through a REST API endpoint. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: focuses on exporting individual vulnerability records via API, not the scanning process itself.
  • Vulnerability Label ManagersAssigns or modifies labels on multiple scan vulnerabilities at once through a single API call. **Distinct from Vulnerability Scanning:** Distinct from Vulnerability Scanning: focuses on batch label management of existing findings, not the scanning process itself.
  • Vulnerability Retesters3 个子标签Tools that trigger new scans for specific vulnerabilities to verify remediation status. **Distinct from Vulnerability Scanning:** Distinct from general vulnerability scanning: focuses on the re-verification of specific existing findings rather than initial discovery.
  • Vulnerable Product DetectionIdentification of vulnerable software through static version checks and package analysis. **Distinct from Vulnerability Scanning:** Distinct from general Vulnerability Scanning by focusing specifically on version-based product identification
  • Web Application PipelinesAutomated sequences of tools specifically designed to detect CVEs and injection flaws in web endpoints. **Distinct from Vulnerability Scanning:** Focuses on the orchestration of web-specific probes and flaw detection rather than container image analysis