Compliance Open Source Projects
Browse 194 Compliance open source projects, ranked by GitHub stars. Find the most popular Compliance tools and libraries.
wazuh/wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Metrics details
| Stars | 16,214 |
CISOfy/lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Metrics details
| Stars | 16,030 |
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Metrics details
| Stars | 14,317 |
open-policy-agent/opa
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
Metrics details
| Stars | 12,001 |
codenotary/immudb
immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history
Metrics details
| Stars | 9,005 |
bridgecrewio/checkov
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Metrics details
| Stars | 8,878 |
aquasecurity/tfsec
Tfsec is now part of Trivy
Metrics details
| Stars | 7,023 |
cloud-custodian/cloud-custodian
Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
Metrics details
| Stars | 6,030 |
deepfence/ThreatMapper
Open Source Cloud Native Application Protection Platform (CNAPP)
Metrics details
| Stars | 5,303 |
ossec/ossec-hids
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
Metrics details
| Stars | 5,033 |
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Metrics details
| Stars | 4,272 |
aquasecurity/cloudsploit
Cloud Security Posture Management (CSPM)
Metrics details
| Stars | 3,755 |
thephpleague/csv
CSV data manipulation made easy in PHP
Metrics details
| Stars | 3,480 |
yannh/kubeconform
A FAST Kubernetes manifests validator, with support for Custom Resources!
Metrics details
| Stars | 3,117 |
inspec/inspec
InSpec: Auditing and Testing Framework
Metrics details
| Stars | 3,082 |
ComplianceAsCode/content
Security automation content in SCAP, Bash, Ansible, and other formats
Metrics details
| Stars | 2,769 |
Bearer/bearer
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Metrics details
| Stars | 2,705 |
0x6d69636b/windows_hardening
HardeningKitty and Windows Hardening Settings
Metrics details
| Stars | 2,637 |
4ndersonLin/awesome-cloud-security
🛡️ Awesome Cloud Security Resources ⚔️
Metrics details
| Stars | 2,469 |
usnistgov/macos_security
macOS Security Compliance Project
Metrics details
| Stars | 2,421 |
ballerine-io/ballerine
Open-source infrastructure and data orchestration platform for risk decisioning
Metrics details
| Stars | 2,407 |
OPCFoundation/UA-.NETStandard
OPC Unified Architecture .NET Standard
Metrics details
| Stars | 2,347 |
tamasfe/taplo
A TOML toolkit written in Rust
Metrics details
| Stars | 2,338 |
rancher/rke2
Metrics details
| Stars | 2,279 |
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Metrics details
| Stars | 2,053 |
Neo23x0/auditd
Best Practice Auditd Configuration
Metrics details
| Stars | 1,868 |
OpenSCAP/openscap
NIST Certified SCAP 1.2 toolkit
Metrics details
| Stars | 1,772 |
bytedance/appshark
Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.
Metrics details
| Stars | 1,746 |
truevault/hipaa-compliance-developers-guide
A developers guide to HIPAA compliance and application development.
Metrics details
| Stars | 1,744 |
project-copacetic/copacetic
🧵 CLI tool for directly patching container images!
Metrics details
| Stars | 1,680 |
nginx/njs
A subset of JavaScript language to use in nginx
Metrics details
| Stars | 1,590 |
nsacyber/Windows-Secure-Host-Baseline
Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber
Metrics details
| Stars | 1,590 |
strongdm/comply
Compliance automation framework, focused on SOC2
Metrics details
| Stars | 1,563 |
HummerRisk/HummerRisk
HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。
Metrics details
| Stars | 1,510 |
liangkangnan/tinyriscv
A very simple and easy to understand RISC-V core.
Metrics details
| Stars | 1,497 |
securitybunker/databunker
Secure Vault for Customer PII/PHI/PCI/KYC Records
Metrics details
| Stars | 1,474 |
lunasec-io/lunasec
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
Metrics details
| Stars | 1,468 |
terraform-compliance/cli
a lightweight, security focused, BDD test framework against terraform.
Metrics details
| Stars | 1,459 |
aws-cloudformation/cloudformation-guard
Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0
Metrics details
| Stars | 1,384 |
datafolklabs/cement
Application Framework for Python
Metrics details
| Stars | 1,348 |
tmobile/pacbot
PacBot (Policy as Code Bot)
Metrics details
| Stars | 1,310 |
stelligent/cfn_nag
Linting tool for CloudFormation templates
Metrics details
| Stars | 1,308 |
square/sudo_pair
Plugin for sudo that requires another human to approve and monitor privileged sudo sessions
Metrics details
| Stars | 1,272 |
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Metrics details
| Stars | 1,266 |
wazuh/wazuh-docker
Wazuh - Docker containers
Metrics details
| Stars | 1,141 |
mikeroyal/Open-Source-Security-Guide
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
Metrics details
| Stars | 1,094 |
Arudjreis/awesome-security-GRC
Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).
Metrics details
| Stars | 1,062 |
jonrau1/ElectricEye
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
Metrics details
| Stars | 1,044 |
tern-tools/tern
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
Metrics details
| Stars | 1,017 |
fossology/fossology
FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and web ui are provided to give you a compliance workflow. License, copyright and export scanners are tools used in the workflow.
Metrics details
| Stars | 1,008 |
usnistgov/OSCAL
Open Security Controls Assessment Language (OSCAL)
Metrics details
| Stars | 929 |
Macjutsu/super
S.U.P.E.R.M.A.N. optimizes the macOS software update experience.
Metrics details
| Stars | 884 |
dev-sec/linux-baseline
DevSec Linux Baseline - InSpec Profile
Metrics details
| Stars | 875 |
privacyradius/gdpr-checklist
The GDPR Checklist
Metrics details
| Stars | 774 |
thephpleague/period
PHP's time range API
Metrics details
| Stars | 733 |
kibitzr/kibitzr
Personal Web Assistant
Metrics details
| Stars | 715 |
Normation/rudder
Rudder is a configuration and security automation platform. Manage your Cloud, hybrid or on-premises infrastructure in a simple, scalable and dynamic way.
Metrics details
| Stars | 697 |
bmarsh9/gapps
Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking
Metrics details
| Stars | 687 |
Privado-Inc/privado
Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.
Metrics details
| Stars | 651 |
marcinguy/betterscan-ce
Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners + OpenAI GPT with One Report (Code, IaC) - Betterscan Community Edition (CE)
Metrics details
| Stars | 635 |
