Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
- Language
- Go
- Licence
- Apache-2.0
- Stars
- 38k
- Latest
- v0.75.0
- Last push
- 2026-10-06
Check dependencies and container images against databases of known vulnerabilities.
Changes in this category (RSS)
| Tool | Stars | Licence | Terms | Self-hosted | Language | Latest | Last push |
|---|---|---|---|---|---|---|---|
| Trivy | 38k | Apache-2.0 | Open source | No | Go | v0.75.0 | 2026-10-06 |
| Grype | 13k | Apache-2.0 | Open source | No | Go | v0.120.0 | 2026-10-05 |
| OSV-Scanner | 11k | Apache-2.0 | Open source | No | Go | v2.6.0 | 2026-10-05 |
| Clair | 11k | Apache-2.0 | Open source | No | Go | v4.9.0 | 2026-09-30 |
| Dependency-Check | 7.7k | Apache-2.0 | Open source | No | Java | v13.0.0 | 2026-10-05 |
5 tools
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
A vulnerability scanner for container images and filesystems
Vulnerability scanner written in Go which uses the data provided by https://osv.dev
Vulnerability Static Analysis for Containers
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.