An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with trivy

A curated list of projects in awesome lists tagged with trivy .

https://github.com/walidshaari/certified-kubernetes-security-specialist

Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.

apparmor certification cks ckss exam-objectives falco kernel-hardening kube-bench kube-hunter kubernetes kubernetes-security mitre-attack open-policy-agent os-footprint pod pod-security-policy policy seccomp security trivy

Last synced: 15 May 2025

https://github.com/walidshaari/Certified-Kubernetes-Security-Specialist

Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.

apparmor certification cks ckss exam-objectives falco kernel-hardening kube-bench kube-hunter kubernetes kubernetes-security mitre-attack open-policy-agent os-footprint pod pod-security-policy policy seccomp security trivy

Last synced: 08 May 2025

https://github.com/HummerRisk/HummerRisk

HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

cloud-custodian cloud-native cloud-native-security compliance compliance-as-code cspm k8s-security kubernetes-security prowler sbom security trivy vulnerability

Last synced: 01 May 2025

https://github.com/hummerrisk/hummerrisk

HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

cloud-custodian cloud-native cloud-native-security compliance compliance-as-code cspm k8s-security kubernetes-security prowler sbom security trivy vulnerability

Last synced: 14 May 2025

https://github.com/komodorio/validkube

ValidKube combines the best open-source tools to help ensure Kubernetes YAML best practices, hygiene & security.

aws aws-lambda golang kubernetes kubeval opensource reactjs s3-bucket serverless trivy typescript yaml

Last synced: 16 May 2025

https://github.com/ChristofferNissen/helmper

Import Helm Charts to OCI registries, optionally with vulnerability patching

copacetic cosign go helm kubernetes oci oras trivy

Last synced: 12 Sep 2025

https://github.com/kac89/vulnrepo

VULNRΞPO - Free vulnerability report generator and repository end-to-end encrypted. Complete templates of issues, CWE, CVE, MITRE ATT&CK, PCI DSS, issues import Nmap/Nessus/Burp/OpenVAS/Bugcrowd/Trivy, Jira export, TXT/JSON/MARKDOWN/HTML/PDF report, attachments, automatic changelog, statistics, vulnerability management, methodologies and much more!

angular bugbounty burpsuite cve cwe end-to-end-encryption mitre-attack nessus nmap openvas pci-dss pentesting security security-team security-tool trivy vulnerability-assessment vulnerability-management vulnerability-report vulnerability-research

Last synced: 03 Apr 2025

https://github.com/christoffernissen/helmper

Import Helm Charts to OCI registries, optionally with vulnerability patching

copacetic cosign go helm kubernetes oci oras trivy

Last synced: 12 Apr 2025

https://github.com/m9sweeper/m9sweeper

m9sweeper is a free and easy kubernetes security platform.

containers docker falco kube-bench kube-hunter kubernetes kubesec security trivy

Last synced: 11 May 2025

https://github.com/aquasecurity/harbor-scanner-trivy

Use Trivy as a plug-in vulnerability scanner in the Harbor registry

harbor harbor-pluggable-scanners harbor-registry scanner-adapter trivy vulnerability-scanner

Last synced: 08 Jul 2025

https://github.com/dbsystel/trivy-vulnerability-explorer

Web application that allows to load a Trivy report in json format and displays the vulnerabilities of a single target in an interactive data table.

hacktoberfest report scan trivy vulnerability

Last synced: 24 Dec 2025

https://github.com/edersonbrilhante/vilicus

Vilicus is an open source tool that orchestrates security scans of container images(docker/oci) and centralizes all results into a database for further analysis and metrics.

anchore cicd clair docker docker-image docker-scanner golang oci oci-image oci-scanner scan-images security security-scanner security-tools security-vulnerability trivy vilicus

Last synced: 15 Apr 2025

https://github.com/mchmarny/vimp

Compare data from multiple vulnerability scanners to get a more complete picture of potential exposures.

artifact container cve gcp grype registry snyk trivy vulnerability

Last synced: 28 Jun 2025

https://github.com/praveensirvi1212/devops_masterpiece-ci-with-jenkins

DevOps-MasterPiece Project using Git, GitHub, Jenkins, Maven, JUnit, SonarQube, Jfrog Artifactory, Docker, Trivy, AWS S3, Docker Hub, GitHub CLI, EKS, ArgoCD, Prometheus, Grafana, Slack and Hashicorp Vault

argocd artifactory cicd docker git github grafana java jenkins kubernetes prometheus slack sonarqube trivy

Last synced: 06 Aug 2025

https://github.com/crazy-max/ghaction-container-scan

GitHub Action to check for vulnerabilities in your container image

docker github-actions sarif-report security-tools trivy vulnerability-scanners

Last synced: 06 Apr 2025

https://github.com/praveensirvi1212/DevOps_MasterPiece-CI-with-Jenkins

DevOps-MasterPiece Project using Git, GitHub, Jenkins, Maven, JUnit, SonarQube, Jfrog Artifactory, Docker, Trivy, AWS S3, Docker Hub, GitHub CLI, EKS, ArgoCD, Prometheus, Grafana, Slack and Hashicorp Vault

argocd artifactory cicd docker git github grafana java jenkins kubernetes prometheus slack sonarqube trivy

Last synced: 06 Aug 2025

https://github.com/lazy-actions/gitrivy

GitHub Issue + Trivy Action

docker github-actions security trivy typescript

Last synced: 13 May 2025

https://github.com/snigdhasambitak/cks

Practice questions for Certified Kubernetes Security Specialist (CKS) exam

apparmor audit-log cks falco kube-bench kubernetes opa runsc trivy

Last synced: 24 Feb 2025

https://github.com/thriving-dev/java-library-template

🎨 Java library template • Gradle Kotlin DSL • GitHub Actions CI/CD to build, release & publish to Maven Central • Renovate • Trivy • Javadoc (Pages) • Issue & PR Templates

github-actions github-pages github-template github-templates gradle gradle-kotlin-dsl gradle-multi-project gradle-publish gradle-release java java-library javadoc library maven-central renovate repository-template template trivy trivy-scan

Last synced: 25 Apr 2025

https://github.com/k1low/trivy-db-to

trivy-db-to is a tool for migrating/converting vulnerability information from Trivy DB to other datasource.

migration-tool mysql postgresql trivy

Last synced: 14 Apr 2025

https://github.com/akihirosuda/vexllm

silence negligible CVE alerts using LLM

llm trivy vex

Last synced: 16 Mar 2025

https://github.com/hnts/vulnerability-exporter

A Prometheus Exporter for managing vulnerabilities in kubernetes by using trivy

kubernetes prometheus prometheus-exporter trivy vulnerability-management

Last synced: 14 Mar 2025

https://github.com/m-mizutani/vulnivore

GitHub issue manager from vulnerability scan results for private repositories

go sarif security trivy vulnerability-management

Last synced: 27 Apr 2025

https://github.com/jz543fm/kali-dockerized

Kali Linux in Docker + Ubuntu 22.04 in Docker for Bug Bounty, Penetration Testing, Security Research, Computer Forensics and Reverse Engineering. Kali Linux inside with Docker with or without support with systemd, repository also contains Proof of Concept with kind (Kubernetes in Docker) to test Kali Linux with enabled systemd in K8s cluster

bug-bounty buildkit computer-forensics cybersecurity docker docker-compose docker-kali-linux dockerfile kali kali-linux makefile pentesting-tools security-tools security-vulnerability systemd trivy ubuntu vulnerability-detection vulnerability-scanners

Last synced: 21 Apr 2025

https://github.com/radiofrance/dib

An opinionated docker image builder

docker goss kaniko trivy

Last synced: 26 Dec 2025

https://github.com/sighupio/trivy-offline

Trivy offline builder. Fits perfectly in your CI System

cicd drone hacktoberfest quay sdlc security trivy

Last synced: 11 Mar 2025

https://github.com/adrianliechti/devkube

Bootstrap Kubernetes with Batteries Included - locally or in the cloud

aks aws azure cert-manager cloud devex devops digitalocean eks grafana kubernetes linkerd linode loki prometheus tekton tempo trivy vault vultr

Last synced: 02 Jan 2026

https://github.com/praduman8435/devsecops-in-action

🚀 The Ultimate DevSecOps Project: Learn how to integrate security, automation, and observability in Kubernetes with AWS, ArgoCD & Prometheus!

argocd cicd devsecops grafana jenkins kubernetes prometheus sonarqube terraform trivy

Last synced: 01 Aug 2025

https://github.com/turbot/steampipe-plugin-trivy

Use SQL to instantly query advisories, vulnerabilities, packages, findings and more using Trivy. Open source CLI. No DB required.

backup etl hacktoberfest postgresql postgresql-fdw sql sqlite steampipe steampipe-plugin trivy zero-etl

Last synced: 22 Apr 2025

https://github.com/aleksandr-kotlyar/python_and_gitlab

Examples of gitlab-ci jobs, pytest slack integration, pylint-check jobs, gitlab-artifacts, parametrization-tests, multithread execution for methods, sitemap checking links status. Mirrored from gitlab.

allure allure-report azure-pipelines bandit gitlab gitlab-ci gitlabci multithread parametrization-tests pylint pytest python safety security-audit sitemap-checking slack slack-integration test-parametrization trivy

Last synced: 28 Oct 2025

https://github.com/emirhandogandemir/software-supply-chain-security-java

This repo contains the technology stack and its usage for software supply chain security of a Java application

cosign dependency-scanning helm image-scanning jib-maven-plugin kyverno sbom sonarqube supply-chain-security trivy

Last synced: 24 Apr 2025

https://github.com/jenkinsci/harbor-plugin

Harbor Plugin for Jenkins

harbor trivy vulnerability

Last synced: 02 Apr 2025

https://github.com/lpsm-dev/azure-pipelines

✨ Azure DevOps Pipeline - Docker Build, Trivy Scan, Secret Detection, Sonar, Kubernetes Deploy and others Steps

app-service azure azure-pipelines build commit-lint deploy docker gitleaks kubernetes pipeline sonarqube trivy

Last synced: 25 Jul 2025

https://github.com/lreimer/secure-devex22

Demo repository for my talk at the Heise Developer Experience 2022 conference.

checkov clean-code code-quality devsecops docker kubernetes lint security security-tools snyk sonarqube static-analysis terraform tilt trivy zap-api

Last synced: 02 Aug 2025

https://github.com/dirien/trivy-plugin-ui

Simple Trivy UI plugin written in Rust

plugin rust trivy ui

Last synced: 11 Apr 2025

https://github.com/zufardhiyaulhaq/asdf-trivy

Trivy plugin for the asdf version manager

asdf asdf-plugin security security-tools trivy

Last synced: 12 Apr 2025

https://github.com/mfreeman451/trivy-streamlit

A streamlit-based app for trivy scanner results 🔒

k8s scanner security streamlit-application trivy

Last synced: 23 Oct 2025

https://github.com/flavienbwk/trivy-docker-compose

Deployment-ready docker configuration and instructions to use Trivy on your infrastructure and CIs.

ci docker docker-compose gitlab offline-capable trivy vulnerability-scanners

Last synced: 23 Mar 2025

https://github.com/homoluctus/ecranner

Scan the vulnerability of Docker images stored in ECR

aws docker ecr python security trivy

Last synced: 31 Oct 2025

https://github.com/aquasecurity/katacoda-scenarios

Katacoda scenarios for Aqua's open source projects

examples kubernetes security starbuard tracee trivy

Last synced: 13 Oct 2025

https://github.com/adenilson365/gitops-argocd

Pipeline de GitOps com implementação helm, aplicação com Observabilidade, Alerta, Resposta a Alertas. Tecnologias: ArgoCD, Helm, Prometheus, Grafana, Jaeger, Kubernetes, Docker, Python, GitHub Actions, Trivy, SonarCloud.

argocd docker git-ops grafana helm jaeger kuebernetes observability prometheus sonarcloud tracing trivy

Last synced: 14 Jun 2025

https://github.com/pirate-emperor/azure-netflix

Azure-Netflix: A DevSecOps CI/CD pipeline project that builds, tests, and deploys a Netflix-inspired web app on Azure. Features Jenkins automation, SonarQube analysis, Docker, security scans with Trivy and OWASP, and deployment via Kubernetes, Prometheus, and Grafana.

azure ci-cd devops docker grafana jenkins kubernetes owasp prometheus sonarqube terraform trivy web-application

Last synced: 28 Oct 2025

https://github.com/tks-devops/devops-nursery-to-graduation

"DevOps: Nursery to Graduation" is a comprehensive guide that takes you on a journey from the very basics to advanced concepts of DevOps. Blog-CloudCraft-with-TK

cicd docker git git-repository gitlab-ci grafana jenkins kubernetes linux maven owasp owasp-dependencycheck trivy

Last synced: 05 Oct 2025

https://github.com/arup-g/url-shortener-with-go

URL shortener application, utilizing MongoDB for the database, Go for the backend, and HTML/CSS/JavaScript for the frontend. The CI/CD pipeline is managed with Jenkins, and security analysis is conducted using Trivy, Sonarqube. The application is built and pushed to AWS ECR and deployed on EKS using Helm charts.

aws-ecr aws-eks-cluster cloudformation docker docker-compose golang helm-charts html jenkins kubernetes mongodb sonarqube trivy

Last synced: 28 Jun 2025

https://github.com/ryosukedtomita/devsecops-demo-aws-ecs

GITHUB ACTIONS and devsecops tools document and demo.

aqua devsecops ghalint github-comment github-pages githubactions semgrep trivy

Last synced: 14 Jun 2025

https://github.com/odennav/server-health-monitoring-pipeline

Deploy shell scripts to Linux servers and send system resource-usage updates to Slack for real-time monitoring

ansible ansible-playbook ansible-role cpu-monitoring disk-usage docker gogs health-check ipmitool jenkins load-testing memory-management slack sonarqube trivy

Last synced: 17 Oct 2025

https://github.com/sugam-arora/zomeal

Welcome to Zomeal, your ultimate culinary guide! Discover the finest eateries and hidden gems in your city with Zomeal. Whether you're craving a quick bite or a gourmet experience, Zomeal connects you to flavors that delight and dishes that inspire. Embark on a delicious journey with us and elevate your dining adventures!

devops devsecops devsecops-pipeline docker git jenkins kubernetes nodejs npm owasp sonarqube trivy zomato zomatoclone

Last synced: 25 Oct 2025

https://github.com/frnn4268/k8s_cloud-native-pg_trivy-operator

This repository contains auxiliary tooling for managing PostgreSQL clusters on Kubernetes, including CloudNativePG, Trivy Operator, and Cert Manager. It simplifies deployment, operation, and security scanning of containerized applications, providing examples and automation through Taskfiles.

automation backup cert-manager cloudnative devops helm kubernetes postgresql security trivy

Last synced: 08 Aug 2025

https://github.com/ibtisam-iq/Agri2Ops

DevOps Unboxed: Tool-specific hands-on projects—Jenkins, Docker, Terraform, and more—that showcase my transition and expertise

ansible docker jenkins kubernetes maven nexus sonarqube terraform trivy

Last synced: 30 Sep 2025

https://github.com/devwithkrishna/trivy-to-scan-all-docker-images-on-dockerofkrishnadhas

trivy to scan for vulnerabilities on all docker images in dockerofkrishnadhas dockerhub account

docker github python security-tools trivy vulnerability-detection

Last synced: 31 Dec 2025

https://github.com/ashutosh0x/aardvark-security-scanner

An AI-powered security scanning system with automated triage, sandbox validation, and patch suggestions. Integrates Semgrep, Bandit, Trivy with LLM analysis for comprehensive vulnerability detection and remediation.

ai automated-patching bandit cybersecurity devsecops docker github-actions go javascript llm openai python sandbox security security-automation security-research security-tools semgrep trivy vulnerability-scanning

Last synced: 10 Nov 2025

https://github.com/rohandeb2/wonderlust-

🚀 Complete DevSecOps Pipeline Implementation | MERN Stack Application with Jenkins CI/CD, GitOps using ArgoCD, Kubernetes on AWS EKS, Security Scanning (SonarQube, OWASP, Trivy), Infrastructure as Code with Terraform, and Full Monitoring Stack

argocd aws-cli ci-cd-pipeline devops devsecops docker grafana helm jenkins kubernetes prometheus sonarqube trivy yaml-configuration

Last synced: 30 Dec 2025

https://github.com/vsingh55/devsecops-pipeline

DevSecOps Pipeline ensures secure, automated, and continuously monitored CI/CD processes on GCloud. It integrates security by design, leverages automation through Jenkins and Docker, and employs continuous monitoring with Prometheus and Grafana to maintain application and infrastructure health.

automation bash devsecops docker dockerhub gcp gmail graphana kubernetes prometheus security sonarqube terraform terraform-module trivy

Last synced: 01 Jul 2025

https://github.com/vsingh55/DevSecOps-Pipeline

DevSecOps Pipeline Pro ensures secure, automated, and continuously monitored CI/CD processes on GCloud. It integrates security by design, leverages automation through Jenkins and Docker, and employs continuous monitoring with Prometheus and Grafana to maintain application and infrastructure health.

automation devsecops docker dockerhub gcp gmail graphana kubernetes prometheus security sonarqube terraform trivy

Last synced: 20 Jul 2025

https://github.com/ibtisam-iq/nectar

Nectar: A meticulously curated resource covering all you need to know about DevOps tools, from basics to mastery

ansible argocd bash-scripting databases docker git gitlab grafana kubernetes maven nginx-server prometheus python-scripting sonarqube terraform tomcat-server trivy yaml

Last synced: 19 Jun 2025

https://github.com/fleaz/trivy-renderer

Render the CRDs from the Trivy Operatr as ASCII tables in your terminal

kubernetes trivy trivy-operator

Last synced: 03 Jul 2025

https://github.com/htekgulds/trivy-dashboard

Simple GUI for the Kubernetes Reports Trivy Operator Generates

dashboard kubernetes nextjs react trivy trivy-operator vulnerability

Last synced: 12 Jun 2025

https://github.com/yash509/do-and-dso-phases

It contains the various Phases that are used in DevOps and DevSecOps

aws azure cloud devops devops-pipeline devops-tools devsecops docker gcp git grafana jenkins kubernetes prometheus sonarqube trivy

Last synced: 30 Dec 2025

https://github.com/aymanek24/devsecops_netflix_monitoring-alerting

This DevSecOps Project integrates security into the software development lifecycle, automating security measures like vulnerability scanning and compliance checks. It emphasizes secure software delivery through DevOps practices and collaboration between development, security, and operations teams, ensuring continuous monitoring and testin.

aws aws-ec2 cloud dependecy-check devops docker docker-container github grafana npm-install prometheus prometheus-exporter sonarqube sonarqube-quality-gates trigger-events trivy

Last synced: 23 Jul 2025

https://github.com/lpsm-dev/personal-resume

🦑 [Portifolio] - This is a simples npm package of my personal resume in a CLI way

cli docker github js node nodejs npm personal resume resume-app resume-builder trivy

Last synced: 22 Feb 2025

https://github.com/khaledhawil/full-devops-project-islamic-app

A production-ready Islamic application demonstrating enterprise-level DevOps practices with full CI/CD automation, containerization, and GitOps deployment.

argocd bash docker docker-compose git github jenkins k8s linux nginx trivy vscode webhook

Last synced: 30 Dec 2025

https://github.com/bjwrd/ci-cd

Including CICD Pipeline Deployments

cicd docker flask jenkins kubernetes trivy

Last synced: 23 Mar 2025

https://github.com/bsindjui1/devsecops-pipeline-demo

End-to-end DevSecOps pipeline demo: Terraform, GitHub Actions, Checkov, Trivy, AWS

aws checkov devsecops docker github-actions terraform trivy

Last synced: 30 Dec 2025

https://github.com/devwithkrishna/create-jenkins-docker-image-and-publish-periodically

Create jenkins docker images and build them periodicaly and scan using trivy

configuration-as-code docker dockerfile dockerhub groovy jenkins plugins trivy

Last synced: 30 Oct 2025

https://github.com/mirsafari/trivy-lens

Trivy Lens is a TUI (terminal user interface) for exploring Kubernetes container vulnerability reports generated by Trivy Operator. It offers an interactive, filterable view of CVEs (Common Vulnerabilities and Exposures) reported in your cluster, along with a simple way to track whitelisted CVEs.

bubbletea cve golang kubernetes trivy trivy-operator

Last synced: 13 Jul 2025

https://github.com/notyusheng/open-webui_secure

An effort to remove all critical and high CVE vulnerabilities from the popular LLM web interface open-webui.

cve docker docker-compose open-webui trivy

Last synced: 08 Mar 2025

https://github.com/woozymasta/pkci

Pumped Kaniko Container Image for Continuous Integration

bash build-tool busybox ci cicd cosign crane docker gomplate helm jq jsonnet kaniko kubectl notary pipeline podman tanka tokei trivy

Last synced: 31 Mar 2025

https://github.com/vaibhavbansal26/devsecops-foodapp

Deploying Food Delivery App - Terraform, Jenkins, SonarQube, Trivy, Docker, Prometheus, Grafana, Helm, React Js

docker grafana helm jenkins prometheus reactjs sonarqube terrraform trivy

Last synced: 30 Dec 2025

https://github.com/rahuldongre-us/python-prometheus-grafana-docker

Easily monitor your Python applications like a pro using Prometheus, Grafana, and Docker – all in one streamlined setup. This project offers a plug-and-play observability stack to track key metrics, set up alerting, and visualize real-time performance dashboards for your Python services.

alert checkov fastapi grafana monitoring observability prometheus python3 trivy

Last synced: 08 Oct 2025

https://github.com/notyusheng/transync

A tool for batch-translating .xlsx spreadsheets from Arabic to English using a locally hosted LLM in LM Studio

docker docker-compose fastapi lm-studio mistral openai openpyxl streamlit translate trivy

Last synced: 19 Apr 2025

https://github.com/vaibhavbansal26/devsecops-moviebooking

Full Deployment Pipe - Terraform, EC2, Amazon EKS, Docker, Jenkins, SonarQube, Owasp, Trivy, AgroCD, Kubernetes

agrocd docker ec2 eks jenkins kubernetes reactjs sonarqube terraform trivy

Last synced: 30 Dec 2025

https://github.com/prajwalchapke055/amazon-prime-clone-devsecops-project

This project automates the deployment of an Amazon Prime Clone using GitHub, Jenkins, SonarQube, Trivy, and Docker. Terraform provisions AWS infrastructure, Helm and ArgoCD handle deployments to AWS EKS, and Prometheus with Grafana enables monitoring. It demonstrates a complete CI/CD pipeline with security, scalability, and real-time monitoring.

argocd aws docker dockerhub git github grafana helm jenkins npm owasp prometheus sonarqube terraform trivy vscode

Last synced: 30 Dec 2025

https://github.com/yahialm/cicd-pipeline-with-jenkins-argocd-sonar-and-k8s

Full implementation of a CI/CD pipeline using Jenkins for Continuous integration and ArgoCD to keep the software product in a deployable state. The project was done locally on VirtualBox and a K3s cluster setup manually on Ubuntu Server VMs.

argocd build-automation cicd devops devsecops docker gitops jenkins owasp-dependencycheck sonarqube spring-boot test-automation trivy

Last synced: 06 Apr 2025

https://github.com/that-prod-guy/cicd-todo-application

A complete Jenkins CI/CD Pipeline of a Full-Stack to-do Application.

docker jenkins owasp-dependencycheck sonarqube trivy

Last synced: 17 Jul 2025

https://github.com/mysticrenji/aws-exploration

Repository contains my tryouts with EKS with OSS security tools - Trivy, Kube-bench, Falco

aws csi-driver eks falco kube-bench kubernetes ssm terraform trivy

Last synced: 05 Nov 2025

https://github.com/gkhays/py-docker-trivy

Scan an SBOM using the Trivy Docker container

docker python sbom trivy

Last synced: 12 Jun 2025