Compliance Open Source Projects

Browse 194 Compliance open source projects, ranked by GitHub stars. Find the most popular Compliance tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 194 projects
16,214 stars

wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Metrics details
Stars16,214
16,030 stars

CISOfy/lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

Metrics details
Stars16,030
14,317 stars

prowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Metrics details
Stars14,317
12,001 stars

open-policy-agent/opa

Open Policy Agent (OPA) is an open source, general-purpose policy engine.

Metrics details
Stars12,001
9,005 stars

codenotary/immudb

immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history

Metrics details
Stars9,005
8,878 stars

bridgecrewio/checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Metrics details
Stars8,878
7,023 stars

aquasecurity/tfsec

Tfsec is now part of Trivy

Metrics details
Stars7,023
6,030 stars

cloud-custodian/cloud-custodian

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Metrics details
Stars6,030
5,303 stars

deepfence/ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP)

Metrics details
Stars5,303
5,033 stars

ossec/ossec-hids

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

Metrics details
Stars5,033
4,272 stars

intuitem/ciso-assistant-community

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.

Metrics details
Stars4,272
3,755 stars

aquasecurity/cloudsploit

Cloud Security Posture Management (CSPM)

Metrics details
Stars3,755
3,480 stars

thephpleague/csv

CSV data manipulation made easy in PHP

Metrics details
Stars3,480
3,117 stars

yannh/kubeconform

A FAST Kubernetes manifests validator, with support for Custom Resources!

Metrics details
Stars3,117
3,082 stars

inspec/inspec

InSpec: Auditing and Testing Framework

Metrics details
Stars3,082
2,769 stars

ComplianceAsCode/content

Security automation content in SCAP, Bash, Ansible, and other formats

Metrics details
Stars2,769
2,705 stars

Bearer/bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Metrics details
Stars2,705
2,637 stars

0x6d69636b/windows_hardening

HardeningKitty and Windows Hardening Settings

Metrics details
Stars2,637
2,469 stars

4ndersonLin/awesome-cloud-security

🛡️ Awesome Cloud Security Resources ⚔️

Metrics details
Stars2,469
2,421 stars

usnistgov/macos_security

macOS Security Compliance Project

Metrics details
Stars2,421
2,407 stars

ballerine-io/ballerine

Open-source infrastructure and data orchestration platform for risk decisioning

Metrics details
Stars2,407
2,347 stars

OPCFoundation/UA-.NETStandard

OPC Unified Architecture .NET Standard

Metrics details
Stars2,347
2,338 stars

tamasfe/taplo

A TOML toolkit written in Rust

Metrics details
Stars2,338
2,279 stars

rancher/rke2

Metrics details
Stars2,279
2,053 stars

oss-review-toolkit/ort

A suite of tools to automate software compliance checks.

Metrics details
Stars2,053
1,868 stars

Neo23x0/auditd

Best Practice Auditd Configuration

Metrics details
Stars1,868
1,772 stars

OpenSCAP/openscap

NIST Certified SCAP 1.2 toolkit

Metrics details
Stars1,772
1,746 stars

bytedance/appshark

Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.

Metrics details
Stars1,746
1,744 stars

truevault/hipaa-compliance-developers-guide

A developers guide to HIPAA compliance and application development.

Metrics details
Stars1,744
1,680 stars

project-copacetic/copacetic

🧵 CLI tool for directly patching container images!

Metrics details
Stars1,680
1,590 stars

nginx/njs

A subset of JavaScript language to use in nginx

Metrics details
Stars1,590
1,590 stars

nsacyber/Windows-Secure-Host-Baseline

Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber

Metrics details
Stars1,590
1,563 stars

strongdm/comply

Compliance automation framework, focused on SOC2

Metrics details
Stars1,563
1,510 stars

HummerRisk/HummerRisk

HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

Metrics details
Stars1,510
1,497 stars

liangkangnan/tinyriscv

A very simple and easy to understand RISC-V core.

Metrics details
Stars1,497
1,474 stars

securitybunker/databunker

Secure Vault for Customer PII/PHI/PCI/KYC Records

Metrics details
Stars1,474
1,468 stars

lunasec-io/lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

Metrics details
Stars1,468
1,459 stars

terraform-compliance/cli

a lightweight, security focused, BDD test framework against terraform.

Metrics details
Stars1,459
1,384 stars

aws-cloudformation/cloudformation-guard

Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

Metrics details
Stars1,384
1,348 stars

datafolklabs/cement

Application Framework for Python

Metrics details
Stars1,348
1,310 stars

tmobile/pacbot

PacBot (Policy as Code Bot)

Metrics details
Stars1,310
1,308 stars

stelligent/cfn_nag

Linting tool for CloudFormation templates

Metrics details
Stars1,308
1,272 stars

square/sudo_pair

Plugin for sudo that requires another human to approve and monitor privileged sudo sessions

Metrics details
Stars1,272
1,266 stars

owasp-dep-scan/dep-scan

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

Metrics details
Stars1,266
1,141 stars

wazuh/wazuh-docker

Wazuh - Docker containers

Metrics details
Stars1,141
1,094 stars

mikeroyal/Open-Source-Security-Guide

Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

Metrics details
Stars1,094
1,062 stars

Arudjreis/awesome-security-GRC

Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).

Metrics details
Stars1,062
1,044 stars

jonrau1/ElectricEye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

Metrics details
Stars1,044
1,017 stars

tern-tools/tern

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

Metrics details
Stars1,017
1,008 stars

fossology/fossology

FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and web ui are provided to give you a compliance workflow. License, copyright and export scanners are tools used in the workflow.

Metrics details
Stars1,008
929 stars

usnistgov/OSCAL

Open Security Controls Assessment Language (OSCAL)

Metrics details
Stars929
884 stars

Macjutsu/super

S.U.P.E.R.M.A.N. optimizes the macOS software update experience.

Metrics details
Stars884
875 stars

dev-sec/linux-baseline

DevSec Linux Baseline - InSpec Profile

Metrics details
Stars875
774 stars

privacyradius/gdpr-checklist

The GDPR Checklist

Metrics details
Stars774
733 stars

thephpleague/period

PHP's time range API

Metrics details
Stars733
715 stars

kibitzr/kibitzr

Personal Web Assistant

Metrics details
Stars715
697 stars

Normation/rudder

Rudder is a configuration and security automation platform. Manage your Cloud, hybrid or on-premises infrastructure in a simple, scalable and dynamic way.

Metrics details
Stars697
687 stars

bmarsh9/gapps

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

Metrics details
Stars687
651 stars

Privado-Inc/privado

Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.

Metrics details
Stars651
635 stars

marcinguy/betterscan-ce

Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners + OpenAI GPT with One Report (Code, IaC) - Betterscan Community Edition (CE)

Metrics details
Stars635
1-60 of 194 projects
Get A Weekly Email With Trending Compliance Projects
Stay updated on Compliance plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.