cfn_nag VS docker-bench-security

Compare cfn_nag vs docker-bench-security and see what are their differences.

docker-bench-security

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production. (by docker)
Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
cfn_nag docker-bench-security
14 13
1,219 8,894
0.5% 1.3%
0.0 5.9
8 months ago 8 days ago
Ruby Shell
MIT License Apache License 2.0
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

cfn_nag

Posts with mentions or reviews of cfn_nag. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-12-25.

docker-bench-security

Posts with mentions or reviews of docker-bench-security. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-07-21.

What are some alternatives?

When comparing cfn_nag and docker-bench-security you can also consider the following projects:

checkov - Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

hadolint - Dockerfile linter, validate inline bash, written in Haskell

cfn-python-lint - CloudFormation Linter

kube-bench - Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark

SonarQube - Continuous Inspection

aws-secure-environment-accelerator - The AWS Secure Environment Accelerator is a tool designed to help deploy and operate secure multi-account, multi-region AWS environments on an ongoing basis. The power of the solution is the configuration file which enables the completely automated deployment of customizable architectures within AWS without changing a single line of code.

gosec - Go security checker

vscode-cloudformation-snippets - This extension adds snippets for all the AWS CloudFormation resources into Visual Studio Code.

tfsec - Security scanner for your Terraform code