Open source security-automation projects

Every project in the registry tagged security-automation, ranked by real GitHub adoption.

projects 4 combined stars ★ 5.5K refresh nightly
01 open-kritt ★ 2.1K

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.

last push2 days ago languageJavaScript licenseAGPL-3.0
02 fixinventory ★ 2.1K

Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.

last push6 months ago languagePython licenseApache-2.0
03 bomber ★ 624

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

last push7 months ago languageGo licenseMPL-2.0
04 faction ★ 604

Pen Test Report Generation and Assessment Collaboration

last push7 days ago languageJava licenseGPL-2.0

Related tags

← all tags

Frequently asked questions

How many open source security-automation projects are there?

This registry tracks 4 projects tagged security-automation, with 5,452 GitHub stars between them. The most-adopted is open-kritt at 2,146 stars.

Are these security-automation projects free to use?

Yes — 4 of the 4 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which security-automation project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these security-automation projects still maintained?

2 of the 4 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.