Skip to content
View chgl's full-sized avatar
🧊
🧊

Block or report chgl

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

🚨 Security

115 repositories

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

Go 27,195 3,197 Updated Feb 24, 2026

The most scalable and customizable permission server on the market. Fix your slow or broken permission system with Google's proven "Zanzibar" approach. Supports ACL, RBAC, and more. Written in Go, …

Go 5,273 375 Updated Feb 25, 2026

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Python 2,201 390 Updated Jul 14, 2024

A reading list for software supply-chain security.

365 15 Updated Nov 21, 2022

eBPF-based Security Observability and Runtime Enforcement

C 4,436 509 Updated Feb 25, 2026

Example recipes for Kubernetes Network Policies that you can just copy paste

6,114 1,819 Updated Feb 7, 2025

Keyless Git signing using Sigstore

Go 1,064 75 Updated Feb 23, 2026

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Go 8,416 774 Updated Feb 25, 2026

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Python 8,486 1,303 Updated Feb 24, 2026

🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍

Go 1,323 157 Updated Jan 8, 2026

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernet…

Go 11,207 898 Updated Feb 18, 2026

Vulnerability scanning just got lazier

Go 319 10 Updated Feb 10, 2026

The authentication glue you need.

Python 20,274 1,485 Updated Feb 25, 2026

Tools and runtime for launching unmodified container images in Trusted Execution Environments

C 151 50 Updated Jul 31, 2025

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Java 3,617 712 Updated Feb 25, 2026

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.

C# 1,984 193 Updated Feb 20, 2026

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Go 5,200 545 Updated Nov 20, 2025

Constellation is a Kubernetes distribution for confidential computing, securing entire clusters on untrusted infrastructure. Constellation is in maintenance mode. New development continues in Contr…

Go 1,100 61 Updated Jan 22, 2026

All-in-one Kubernetes access manager. User-level credentials, RBAC, SSO, audit logs.

Go 1,175 76 Updated Jan 29, 2026

Operator to deploy confidential containers runtime

Go 152 71 Updated Feb 1, 2026

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-…

Python 1,016 189 Updated Mar 12, 2024

GUAC aggregates software security metadata into a high fidelity graph database.

Go 1,448 193 Updated Feb 25, 2026

OpenSSF Scorecard - Security health metrics for Open Source

Go 5,278 605 Updated Feb 23, 2026

Official GitHub Action for OpenSSF Scorecard.

Go 361 82 Updated Feb 10, 2026

Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powered by a Neo4j database.

Python 3,732 486 Updated Feb 25, 2026

Sigstore Policy Controller - an admission controller that can be used to enforce policy on a Kubernetes cluster based on verifiable supply-chain metadata from cosign

Go 159 69 Updated Feb 16, 2026

Pinniped is the easy, secure way to log in to your Kubernetes clusters.

Go 696 79 Updated Feb 25, 2026

The immutable Linux meta-distribution for edge Kubernetes.

Go 1,655 126 Updated Feb 25, 2026

Language-agnostic SLSA provenance generation for Github Actions

Go 547 172 Updated Feb 21, 2026