Scans SBOMs for vulnerabilities with Grype
☆85Feb 28, 2026Updated this week
Alternatives and similar repositories for vulnerability-operator
Users that are interested in vulnerability-operator are comparing it to the libraries listed below
Sorting:
- Catalogue all images of a Kubernetes cluster to multiple targets with Syft☆221Feb 21, 2026Updated last week
- Vulnerability Scanner Suite based on grype and syft from anchore☆52May 5, 2022Updated 3 years ago
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆14Updated this week
- An query language and interactive tooling to work with SBOM data.☆15Oct 7, 2024Updated last year
- Easily run Conftest, pull remote policies, surface the results, and obtain test metrics☆12Oct 2, 2025Updated 5 months ago
- Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign☆12Sep 15, 2021Updated 4 years ago
- Creates PolicyReports based on the different Trivy Operator CRDs like VulnerabilityReports☆63Feb 23, 2026Updated last week
- vexctl is a tool to attest VEX impact statements☆45Mar 27, 2023Updated 2 years ago
- Generate a score for your sbom to understand if it will actually be useful.☆238Aug 13, 2024Updated last year
- Supply Chain Integrity Model☆106Jun 12, 2023Updated 2 years ago
- ☆17Jan 11, 2022Updated 4 years ago
- This repo. is archived. The utility is now at: https://github.com/CycloneDX/sbom-utility☆60Apr 17, 2023Updated 2 years ago
- A utility to generate SPDX-compliant Bill of Materials manifests☆443Updated this week
- Transparenty Immutable Container Image Tags☆20Jul 5, 2023Updated 2 years ago
- A tool to create, transform and attest VEX metadata☆176Updated this week
- ☆23Mar 13, 2023Updated 2 years ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆24Feb 19, 2026Updated last week
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,450Updated this week
- Takes a software bill of materials and outputs provenance, and activity data from trustypkg.dev☆10May 19, 2025Updated 9 months ago
- A template repository for building external data providers for Gatekeeper.☆12Aug 14, 2023Updated 2 years ago
- GitHub Action to check Docker system status in your workflow☆12Updated this week
- Kontinuous - GitOps for Kubernetes 🥷☆11Feb 9, 2026Updated 3 weeks ago
- Keyless Git signing with cosign!☆11May 12, 2022Updated 3 years ago
- Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the …☆14Jan 31, 2023Updated 3 years ago
- Kubernetes Admission Controller for Image Scanning using OPA☆50Sep 18, 2023Updated 2 years ago
- Flux Subsystem for Argo - Patch Repository☆13Mar 29, 2024Updated last year
- KubeTrivyExporter is Prometheus Exporter that collects all vulnerabilities detected by aquasecurity/trivy in the kubernetes cluster.☆50Feb 25, 2023Updated 3 years ago
- ☆62Updated this week
- agent for handling seccomp descriptors for container runtimes☆47Feb 1, 2024Updated 2 years ago
- Vulnerability scanning just got lazier☆319Updated this week
- A license scanner for container images and filesystems.☆143Updated this week
- A multi scanner for docker images. It drives Clair, Anchore, Trivy, Snyk, Grype, AWS ECR scans and consolidates the results.☆14Jun 23, 2023Updated 2 years ago
- A CLI application to make the use of "kubectl" more convenient☆12Aug 22, 2022Updated 3 years ago
- A Kubewarden Policy that verifies all the signatures of the container images referenced by a Pod☆13Jan 20, 2026Updated last month
- Scan Kubernetes resource files , and helm charts for security configurations issues and best practices.☆205Mar 3, 2023Updated 2 years ago
- Demos and resources of the Istio + Gatekeeper talks at IstioCon 2022 and GitOpsCon 2022☆14Sep 4, 2023Updated 2 years ago
- Diagrams to visually learn Falco and its eBPF probe☆15Jun 24, 2021Updated 4 years ago
- Generate K8s RBAC policies based on e2e test runs☆28Jul 6, 2021Updated 4 years ago
- sysctl/sysfs settings on a fly for Kubernetes Cluster. No restarts are required for clusters and nodes.☆19Aug 24, 2022Updated 3 years ago