anchore-engine
dagda
Our great sponsors
anchore-engine | dagda | |
---|---|---|
3 | 4 | |
1,529 | 1,109 | |
- | - | |
4.0 | 0.0 | |
about 1 year ago | 11 months ago | |
Python | Python | |
Apache License 2.0 | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
anchore-engine
-
A Tool To Advise What Apps Are Out Of Date Per Cluster?
There's also Anchore. - Also another thread w/ resources - https://www.reddit.com/r/kubernetes/comments/bx4w2h/track_outdated_images/.
-
How to Secure Your Kubernetes Clusters With Best Practices
Enable container image scanning in your CI/CD phase to catch known vulnerabilities using tools like clair or Anchore.
- What Vulnerability Scanning Services do you use?
dagda
-
General Docker Troubleshooting, Best Practices & Where to Go From Here
Dagda. A tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in Docker images/containers.
-
Open source container scanning tool to find vulnerabilities and suggest best practice improvements?
https://github.com/eliasgranderubio/dagda 1k stars, updated July 27th, 2021
-
2 Widespread Attacks on Your Containerized Environment and 7 Rules to Prevent it.
Dagda uses a static analysis approach to find viruses, malware, and fake sub-images and trojans. It is based on Red Hat Security Advisories (RHSA) libraries of existing vulnerabilities databases.
-
Am I being crypto-jacked by hackers
Furthermore, there are tools such as https://github.com/eliasgranderubio/dagda.
What are some alternatives?
grype - A vulnerability scanner for container images and filesystems
clair - Vulnerability Static Analysis for Containers
quay - Build, Store, and Distribute your Applications and Containers
Harbor - An open source trusted cloud native registry project that stores, signs, and scans content.
aura - Python source code auditing and static analysis on a large scale
trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
jellyfin-session-kicker - Session kicker after X amount of watch time for Jellyfin
opencve - CVE Alerting Platform
docker-bench-security - The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
vimp - Compare data from multiple vulnerability scanners to get a more complete picture of potential exposures.
ThreatMapper - Open source cloud native security observability platform. Linux, K8s, AWS Fargate and more.
pandora - Pandora is an analysis framework to discover if a file is suspicious and conveniently show the results