Open Policy Agent (OPA) is an open source, general-purpose policy engine.
-
Updated
Aug 7, 2025 - Go
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history
Tfsec is now part of Trivy
A FAST Kubernetes manifests validator, with support for Custom Resources!
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Compliance automation framework, focused on SOC2
🧵 CLI tool for directly patching container images!
Secure Vault for Customer PII/PHI/PCI/KYC Records
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
Evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
A plugin to enforce OPA policies with Envoy
An open source, cloud-native security to protect everything from build to runtime
Open source compliance tool for development platforms.
By scanning CI/CD misconfigurations, Allero helps reduce production issues, harden your security posture and shift-left CI/CD from DevOps to developers.
Speedle is an open source project for access control.
Guardian is universal data access management tool with automated access workflows and security controls across data stores, analytical systems, and cloud products.
A privacy and security engineering toolkit: Discover, understand, pseudonymize, anonymize, encrypt and securely share sensitive and personal data: Privacy and security as code.
Search an SBOM for licenses and the packages they belong to
Add a description, image, and links to the compliance topic page so that developers can more easily learn about it.
To associate your repository with the compliance topic, visit your repo's landing page and select "manage topics."