Aqua Security (@aquasecurity)

Top repositories

1

trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Go
22,757
star
2

tfsec

Tfsec is now part of Trivy
Go
6,659
star
3

kube-bench

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
Go
5,935
star
4

kube-hunter

Hunt for security weaknesses in Kubernetes clusters
Python
4,709
star
5

tracee

Linux Runtime Security and Forensics using eBPF
Go
3,601
star
6

cloudsploit

Cloud Security Posture Management (CSPM)
JavaScript
3,304
star
7

starboard

Moved to https://github.com/aquasecurity/trivy-operator
Go
1,346
star
8

trivy-operator

Kubernetes-native security toolkit
Go
1,249
star
9

microscanner

Scan your container images for package vulnerabilities with Aqua Security
Dockerfile
856
star
10

kubectl-who-can

Show who has RBAC permissions to perform actions on different resources in Kubernetes
Go
810
star
11

trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
Shell
807
star
12

libbpfgo

eBPF library for Go. Powered by libbpf.
Go
731
star
13

chain-bench

An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
Go
725
star
14

cloud-security-remediation-guides

Security Remediation Guides
698
star
15

vuln-list

NVD, Ubuntu, Alpine
408
star
16

btfhub

BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for embedded BTF. This joint effort ensures that even kernels without built-in BTF support can effectively leverage the benefits of eBPF programs, promoting compatibility across various kernel versions.
Go
386
star
17

esquery

An idiomatic Go query builder for ElasticSearch
Go
305
star
18

traceeshark

Deep Linux runtime visibility meets Wireshark
C
244
star
19

trivy-db

Go
224
star
20

kube-query

[EXPERIMENTAL] Extend osquery to report on Kubernetes
Go
223
star
21

harbor-scanner-trivy

Use Trivy as a plug-in vulnerability scanner in the Harbor registry
Go
218
star
22

defsec

Trivy's misconfiguration scanning engine
Go
213
star
23

postee

Simple message routing system that receives input messages through a webhook interface and can enforce actions using predefined outputs via integrations.
Go
201
star
24

fanal

Static Analysis Library for Containers
Go
200
star
25

cloudsec-icons

A collection of cloud security icons ☁️🔒
Go
186
star
26

docker-bench

Checks whether Docker is deployed according to security best practices as defined in the CIS Docker Benchmark
Go
179
star
27

vuln-list-update

Go
173
star
28

manifesto

Use Manifesto to store and query metadata for container images.
Go
164
star
29

tfsec-pr-commenter-action

Add comments to pull requests where tfsec checks have failed
Go
164
star
30

linux-bench

Checks whether a Linux server according to security best practices as defined in the CIS Distribution-Independent Linux Benchmark
Go
152
star
31

go-dep-parser

Dependency Parser for Multiple Programming Languages
Go
144
star
32

lmdrouter

Go HTTP router library for AWS API Gateway-invoked Lambda Functions
Go
135
star
33

appshield

Security configuration checks for popular cloud native applications and infrastructure.
Open Policy Agent
118
star
34

starboard-lens-extension

Lens extension for viewing Starboard security information
TypeScript
117
star
35

trivy-vscode-extension

A VS Code Extension for Trivy
TypeScript
116
star
36

btfhub-archive

The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing the versatility of eBPF programs across different kernel versions.
94
star
37

aqua-helm

Helm Charts For Installing Aqua Security Components
Mustache
86
star
38

table

🧮 Tables for terminals, in Go.
Go
81
star
39

tracee-action

Protect GitHub Actions with Tracee
Open Policy Agent
78
star
40

cfsec

Static analysis for CloudFormation templates to identify common misconfiguration
Go
58
star
41

starboard-octant-plugin

Octant plugin for viewing Starboard security information
Go
57
star
42

deployments

All Aqua deployments options and aquactl configuration
Shell
56
star
43

tfsec-sarif-action

Shell
52
star
44

tfsec-action

Vanilla GitHub action to run tfsec
Shell
52
star
45

trivy-azure-pipelines-task

An Azure Pipelines Task for trivy
TypeScript
46
star
46

community

Aqua Security's open source community
40
star
47

trivy-operator-lens-extension

https://github.com/aquasecurity/trivy-operator
TypeScript
37
star
48

terraform-provider-aquasec

Go
35
star
49

go-version

A Go library for parsing and verifying versions and version constraints.
Go
35
star
50

harbor-scanner-aqua

Aqua Enterprise scanner as a plug-in vulnerability scanner in the Harbor registry
Go
35
star
51

aqua-operator

The aqua-operator is a group of controllers that runs within a Kubernetes or Openshift cluster that provides a means to deploy and manage Aqua Security cluster and Components.
Go
34
star
52

trivy-checks

Go
34
star
53

trivy-java-db

Go
30
star
54

vscode-tfsec

vscode extension for tfsec
TypeScript
30
star
55

trivy-kubernetes

Trivy kubernetes library
Go
29
star
56

trivy-plugin-kubectl

A Trivy plugin that scans the images of a kubernetes resource
Shell
25
star
57

trivy-docker-extension

Docker Desktop Extension for Trivy
TypeScript
20
star
58

trivy-plugin-referrer

Trivy plugin for OCI referrers
Go
20
star
59

trivy-enforcer

[EXPERIMENTAL] Kubernetes Operator for Image Assurance
Go
20
star
60

chain-bench-action

Shell
19
star
61

aqua-aws

The repository not supported any more. Please use this one https://github.com/aquasecurity/deployments
HCL
18
star
62

trivy-pipe

Bitbucket Pipe for running Trivy in a Pipeline
Shell
17
star
63

starboard-operator

The Starboard Operator has moved to the main Starboard repo, and this one is being retired
Go
16
star
64

windows-bench

Checks whether a Windows server according to security best practices as defined in the CIS Distribution-Independent Windows Benchmark
Go
16
star
65

saas-terraform-connection

Terraform modules for CloudSploit Scanner
HCL
14
star
66

trivy-ci-test

Dockerfile
14
star
67

vexhub

13
star
68

saas-api-samples

Sample code snippets for consuming the CloudSploit API
JavaScript
13
star
69

helm-charts

Aqua Open Source Helm Chart Repository
13
star
70

circleci-orb-microscanner

Enables scanning of docker builds in CircleCi for OS package vulnerabilities.
Dockerfile
13
star
71

vim-trivy

Vim Plugin for Trivy
Vim Script
13
star
72

vim-tfsec

List your tfsec issues in the QuickFix window with this plugin.
Vim Script
12
star
73

trivy-aws

Go
11
star
74

trivy-plugin-aqua

Makefile
11
star
75

go-git-pr-commenter

library for adding comments to git PRs
Go
11
star
76

binfinder

Find binary files not installed through package manager
Go
11
star
77

trivy-sarif-demo

JavaScript
9
star
78

cloud-metadata

Common metadata repository for CSPM and TFSec checks
Go
9
star
79

tracee-test-kernels

Kernels for testing tracee CO-RE feature
C
9
star
80

bench-common

Common code for hardening benchmarks
Go
9
star
81

trivy-repo

deb/rpm repository for Trivy
9
star
82

aws-security-hub-plugin

Aqua Security AWS Security Hub plugin
9
star
83

tracee-tester

This is a spin-off from Tracee project responsible for generating the docker image that tests open-source signatures.
Shell
9
star
84

gobard

Unofficial Golang API for Bard Chat.
Go
8
star
85

aqua-dash

Sample Aqua CSP dashboard
Vue
8
star
86

trivy-iac

Go
7
star
87

scan-cve-2018-8115

Python
7
star
88

amazon-eks-devsecops

PHP
7
star
89

pipeline-enforcer-action

TypeScript
7
star
90

intellij-trivy

Trivy Plugin for the JetBrains family of IDEs
Java
7
star
91

go-pep440-version

A golang library for parsing PEP 440 compliant Python versions
Go
7
star
92

tfsec-azure-pipelines-task

An Azure DevOps Task for tfsec
TypeScript
7
star
93

build-security-action

GitHub Action for Aqua Build Security
Shell
7
star
94

go-npm-version

A golang library for parsing npm versions
Go
6
star
95

saas-integrations

CloudSploit third-party integrations
JavaScript
6
star
96

trivy-plugin-attest

Publish SBOM attestation
Go
6
star
97

k8s-node-collector

Go
6
star
98

secfixes-tracker

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker
Python
6
star
99

trivy-module-wordpress

Trivy example module for WordPress
Go
5
star
100

reportgen

PDF reports for Aqua CSP image and host vulnerabilities
Go
5
star