syft

Software inventory tool

Generates detailed visibility into software packages and dependencies to manage vulnerabilities and license compliance.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

GitHub

6k stars
59 watching
585 forks
Language: Go
last commit: almost 2 years ago
Linked from 5 awesome lists

containerscyclonedxdockergogolanghacktoberfestocisbomspdxstatic-analysistool

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
anchore/grypeA tool for detecting vulnerabilities in container images and filesystems8,970
future-architect/vulsA tool to automatically scan and report on vulnerabilities in software systems.11,021
edersonbrilhante/vilicusAn open-source tool that orchestrates security scans of container images and centralizes the results into a database for analysis and metrics.85
albuch/sbt-dependency-checkAutomatically monitors dependencies for known vulnerabilities and generates reports on security issues266
hasherezade/pe-sieveA tool for detecting and analyzing malicious code in executables3,157
linuxserver/docker-swagAn all-in-one web application gateway with Nginx, PHP, and security features2,941
kubescape/kubescapeA platform that analyzes and secures Kubernetes environments throughout the development and deployment lifecycle10,292
zubux/drydockTools for assessing Docker daemon configuration and container security65
aquasecurity/trivyA comprehensive security scanner that identifies vulnerabilities and misconfigurations in various targets such as containers, code repositories, and infrastructure24,010
deepfence/secretscannerA tool that scans container images and file systems for sensitive data such as passwords and keys.3,146
projectdiscovery/nucleiA fast and customizable vulnerability scanner built on a YAML-based DSL.21,054
diego-treitos/linux-smart-enumerationA tool for gathering information about the security of a Linux system to help identify vulnerabilities and potentially escalate privileges.3,462
dominicbreuker/stego-toolkitA collection of steganography tools for solving CTF challenges2,425
snyk/cliA command-line tool that scans and monitors software development projects for security vulnerabilities.4,979
zardus/ctf-toolsA collection of setup scripts and tools for security research.8,580