SaaSHub helps you find the best software and product alternatives Learn more →
Top 17 Go Vulnerability Projects
-
Project mention: Performance Test: Grype 0.70 vs Trivy 0.50 Scan Times – 15% Faster for Alpine Images | dev.to | 2026-04-28
After 120+ benchmark runs across 6 Alpine image variants, 2 hardware configurations, and 3 CI environments, our verdict is clear: Grype 0.70 is 15% faster than Trivy 0.50 for Alpine-based container images, with identical vulnerability detection parity. For teams scanning Alpine images at scale, this speedup translates to thousands of dollars in CI compute savings and hundreds of engineer hours reclaimed per month. If you're only scanning Alpine images, migrate to Grype today—the 15% speedup is worth the migration effort for any team with more than 100 daily scans. For heterogeneous image stacks, Trivy remains the better all-in-one option. We recommend running the benchmark script we provided earlier on your own images to validate the speedup for your specific workload.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
vuls
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
-
Project mention: Performance Test: Grype 0.70 vs Trivy 0.50 Scan Times – 15% Faster for Alpine Images | dev.to | 2026-04-28
How does Clair compare to Grype and Trivy for Alpine image scans?
-
-
bearer
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
-
-
-
horusec
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
-
Open-Source-Security-Guide
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
-
-
-
-
-
-
debcvescan
Debian CVE Scanner is self-contained CVE scanner for DEBIAN distributions written in golang.
-
The project is available here: https://github.com/manuelarte/gowasp
-
shadowspace-curzor
Shadowspace is a cyberrange for active cybersecurity trainings and exercises. Curzor is one of the basics parts of that range - a web app containing multuple security vulnerabilities.
Go Vulnerabilities discussion
Go Vulnerabilities related posts
-
Performance Test: Grype 0.70 vs Trivy 0.50 Scan Times – 15% Faster for Alpine Images
-
Building Secure Docker Images for Production - Best Practices
-
Security starts before the production deployment
-
A tool that scans repos and workout latest version and pull date of installed version + how to lock down repos (via some cluster policy?)
-
Degree vs Certifications
-
Open Source Security Development
-
Open Source Security Guide
-
A note from our sponsor - SaaSHub
www.saashub.com | 8 Jun 2026
Index
What are some of the best open-source Vulnerability projects in Go? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | grype | 12,344 |
| 2 | vuls | 12,172 |
| 3 | clair | 10,994 |
| 4 | CDK | 4,673 |
| 5 | bearer | 2,674 |
| 6 | jaeles | 2,336 |
| 7 | copacetic | 1,635 |
| 8 | horusec | 1,319 |
| 9 | Open-Source-Security-Guide | 1,076 |
| 10 | eraser | 604 |
| 11 | huskyCI | 593 |
| 12 | juicyurls | 49 |
| 13 | bif | 40 |
| 14 | depshub | 34 |
| 15 | debcvescan | 30 |
| 16 | gowasp | 12 |
| 17 | shadowspace-curzor | 7 |