Open source security-tools projects
Every project in the registry tagged security-tools, ranked by real GitHub adoption.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS b
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
🧵 CLI tool for directly patching container images!
An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Pen Test Report Generation and Assessment Collaboration
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
Related tags
Frequently asked questions
How many open source security-tools projects are there?
This registry tracks 9 projects tagged security-tools, with 65,037 GitHub stars between them. The most-adopted is trivy at 37,961 stars.
Are these security-tools projects free to use?
Yes — 9 of the 9 carry an explicit open-source licence across 5 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which security-tools project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these security-tools projects still maintained?
8 of the 9 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.