GitStar
GitHub TrendingTopicsLanguages
/

Container Security GitHub Repositories

Explore popular GitHub repositories tagged “container-security”.

Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.

RepositoriesGitHub topic
Ranked by:Stars

Trending Repositories

wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C++16,5892,445
madhuakula/kubernetes-goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

HTML5,7471,038
cdk-team/CDK

📦 Make security testing of K8s, Docker, and Containerd easier.

Go4,732606
project-copacetic/copacetic

🧵 CLI tool for directly patching container images!

Go1,690122
chaitin/veinmind-tools

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

Go1,651187
Metarget/metarget

Metarget is a framework providing automatic constructions of vulnerable infrastructures.

Python1,411202
vchinnipilli/kubestriker

A Blazing fast Security Auditing tool for Kubernetes

Python1,000109
opengovern/opensecurity

opensecurity: open-source security and compliance. See and secure your cloud, containers, code, networks, deployments, devices. Define your rules, get precise checks, fix gaps fast. Streamlined audits. No fluff.

TypeScript71729
mensfeld/code-on-incus

Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.

Go65454
Vinum-Security/kubernetes-security-checklist

Kubernetes Security Checklist and Requirements - All in One (authentication, authorization, logging, secrets, configuration, network, workloads, dockerfile)

48692
Metarget/awesome-cloud-native-security

awesome resources about cloud native security 🐿

32757
sysdiglabs/kube-psp-advisor

Help building an adaptive and fine-grained pod security policy

Go32741
Metarget/k0otkit

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Shell29951
r0binak/MTKPI

🧰 Multi Tool Kubernetes Pentest Image

Shell26223
jetstack/paranoia

Inspect certificate authorities in container images

Go24310
ellerbrock/docker-security-images

:closed_lock_with_key: Docker Container for Penetration Testing & Security

24035
R3DRUN3/sploitcraft

🏴‍☠️ Hacking Guides, Demos and Proof-of-Concepts 🥷

Jupyter Notebook22527
cynative/cynative

Build your own security agents. Open-source framework for agents with live, read-only access to your infrastructure, with no path to widen it. Reasons across AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system.

Go19028
mikeroyal/OpenShift-Guide

OpenShift Guide. Learn about the Red Hat OpenShift Container Platform, Data Science, Code Ready Containers, Podman, Buildah, and Kubernetes.

Python16746
koslib/awesome-containerized-security

A collection of tools to improve your containerized apps security posture

15216
twistlock/whoc

A container image that exfiltrates the underlying container runtime to a remote server

C13511
VibePod/vibepod-cli

Unified CLI for running AI coding agents in isolated containers. Includes built-in local metrics collection, HTTP traffic tracking, and an analytics dashboard to track agent actions.

Python1307
chaitin/libveinmind

一个由长亭自研,直观而可扩展的容器安全 SDK

Go11718
grantseltzer/karn

Simplifying Seccomp enforcement in containerized or non-containerized apps

Go11312
raoulx24/trivy-operator-dashboard

Trivy Operator Dashboard: A comprehensive tool for Trivy Operator. Offers various dashboards and interactive pages where you can browse and inspect Trivy Reports. Built with C#, .NET 10 (backend), Angular 21, and Node.js 24 (frontend).

C#1008
kajogo777/the-agent-sandbox-taxonomy

An open taxonomy and scoring framework for evaluating AI agent sandboxes: 7 defense layers, 7 threat categories, 3 evaluation dimensions, 27 "sandboxes" scored.

Go967
santhreal/keyhog

GPU-accelerated secret scanner for code, Git history, containers, cloud, browser assets, and CI. 923 detectors, live verification, CUDA, Metal, WGPU.

Rust9012
CloudDefenseAI/falco_extended_rules

Curating Falco rules with MITRE ATT&CK Matrix

Python8516
sandbox-utils/sandbox-run

🔒🐧 Run command in a secure native sandbox (zero deps)

Shell805
inno-devops-labs/DevSecOps-Intro

🚀 DevSecOps intro elective — 10 hands-on labs + 2 bonus hardening OWASP Juice Shop: threat modeling (STRIDE/Threagile), signed commits & secret scanning, SBOM/SCA, SAST + DAST, IaC security (Checkov/KICS), container & supply-chain hardening (Trivy, Cosign), runtime detection with Falco, and DefectDojo vuln management.

Shell79141
GitStar

See what the GitStar community is most excited about today.

Trending

GitHub Trending TodayGitHub Trending WeeklyGitHub Trending Monthly

Languages

Browse all languagesTrending PythonTrending JavaScript

Explore

Browse GitHub topicsAI repositoriesDeveloper tools
© 2026 GitStarGitHub Trending source