Go vulnerability-scanners

Open-source Go projects categorized as vulnerability-scanners

Top 15 Go vulnerability-scanner Projects

vulnerability-scanners
  1. trivy

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    Project mention: Stop shipping insecure Dockerfiles: real devs don’t run as root | dev.to | 2025-05-03
  2. InfluxDB

    InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.

    InfluxDB logo
  3. vuls

    Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

  4. tfsec

    Tfsec is now part of Trivy

    Project mention: 🛡️ Secure, Lint, and Validate Your Terraform Like a Pro | dev.to | 2025-05-19
  5. scan4all

    Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

  6. SecretScanner

    :unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:

  7. trivy-operator

    Kubernetes-native security toolkit

    Project mention: 🛡️ Effective Vulnerability Monitoring in Kubernetes | dev.to | 2024-08-26

    For more details, check out the Trivy Operator documentation and Helm chart repository.

  8. go-dork

    The fastest dork scanner written in Go.

  9. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  10. shortscan

    An IIS short filename enumeration tool

  11. clair-scanner

    Docker containers vulnerability scan

  12. bomber

    Scans Software Bill of Materials (SBOMs) for security vulnerabilities

  13. LogMePwn

    A fully automated, reliable, super-fast, mass scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.

  14. lazytrivy

    Vulnerability scanning just got lazier

  15. vesta

    A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing (by kvesta)

  16. udpx

    Fast and lightweight, UDPX is a single-packet UDP scanner written in Go that supports the discovery of over 45 services with the ability to add custom ones. It is easy to use and portable, and can be run on Linux, Mac OS, and Windows. Unlike internet-wide scanners like zgrab2 and zmap, UDPX is designed for portability and ease of use.

  17. log4shelldetect

    Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class paths inside files

  18. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Go vulnerability-scanners discussion

Log in or Post with

Go vulnerability-scanners related posts

  • Ask HN: Has anyone adopted or seen adoption of RFC8959 secret-token?

    1 project | news.ycombinator.com | 24 Mar 2025
  • Dockerfile Best Practices: Writing Efficient and Secure Docker Images

    1 project | dev.to | 7 Oct 2024
  • 🛡️ Effective Vulnerability Monitoring in Kubernetes

    4 projects | dev.to | 26 Aug 2024
  • Day 25: Container Security with Trivy - My 90 Days of DevOps Journey

    1 project | dev.to | 14 Aug 2024
  • Enhancing Kubernetes Security with Trivy : Day 15 of 50 days DevOps Tools Series

    1 project | dev.to | 24 Jul 2024
  • Docker image vulnerabilities scanning trivy vs synk.io

    1 project | /r/docker | 30 Apr 2023
  • Docker image vulnerabilities scanning trivy vs synk.io

    1 project | /r/cybersecurity | 30 Apr 2023
  • A note from our sponsor - SaaSHub
    www.saashub.com | 24 May 2025
    SaaSHub helps you find the best software and product alternatives Learn more →

Index

What are some of the best open-source vulnerability-scanner projects in Go? This list will help you:

# Project Stars
1 trivy 26,748
2 vuls 11,570
3 tfsec 6,821
4 scan4all 5,674
5 SecretScanner 3,194
6 trivy-operator 1,504
7 go-dork 1,196
8 shortscan 929
9 clair-scanner 856
10 bomber 566
11 LogMePwn 399
12 lazytrivy 289
13 vesta 198
14 udpx 187
15 log4shelldetect 45

Sponsored
InfluxDB – Built for High-Performance Time Series Workloads
InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
www.influxdata.com

Did you know that Go is
the 4th most popular programming language
based on number of references?