Sign inSign up
31 - 60 of 8,081 available results.
HARDENED IMAGE
Recommended

Syft is a CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems with support for multiple output formats and package ecosystems.

10h

100K+

HARDENED IMAGE
Recommended

Grype is a vulnerability scanner for container images and filesystems. It provides fast and accurate vulnerability detection with support for multiple package ecosystems and output formats.

10h

100K+

HARDENED IMAGE
Recommended

Istioctl image for managing Istio deployments

10h

100K+

HARDENED IMAGE
Recommended

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

10h

100K+

HARDENED IMAGE
Recommended

Docker Distribution registry for storing and distributing container images within Harbor

10h

100K+

HARDENED IMAGE
Recommended

OPA is a policy engine that streamlines policy management across your stack for improved development, security and audit capability.

10h

100K+

HARDENED IMAGE
Recommended

OpenFGA is an open source Fine Grained Authorization solution that implements Google's Zanzibar paper, helping you manage complex authorization rules in your applications.

10h

100K+

HARDENED IMAGE
Recommended

TruffleHog is a secrets scanning tool that finds credentials, API keys, and sensitive data in git repositories, filesystems, S3 buckets, and more. Written in Go.

10h

100K+

image

Amazon CloudWatch Agent

19d

1B+

39

HARDENED IMAGE
Recommended

Cilium Standalone DNS Proxy is an alpha component that provides independent DNS proxying capabilities, receiving policy rules from the Cilium agent via gRPC.

10h

100K+

HARDENED IMAGE
Recommended

Kubernetes-native security toolkit that leverages Trivy to continuously scan your Kubernetes cluster for security issues.

10h

100K+

HARDENED IMAGE
Recommended

Notation is a CLI tool for signing and verifying OCI artifacts with trust policies and plugin-based key management.

10h

100K+

HARDENED IMAGE
Recommended

Sidecar for managing OPA instances in Kubernetes.

10h

100K+

HARDENED IMAGE
Recommended

SonarQube is a self-managed, automatic code review tool that systematically helps you deliver clean code.

10h

100K+

HARDENED IMAGE
Recommended

Tailscale lets you securely connect devices and containers without exposing them to the public internet.

10h

100K+

image

Lacework is cloud security for AWS, Azure, GCP and other public and private cloud.

15d

1B+

23

HARDENED IMAGE
Recommended

Policy Controller for Kubernetes, built on Open Policy Agent.

10h

100K+

image

Unprivileged NGINX Dockerfiles

4d

1B+

193

image

Non-immutable installer image for Dynatrace OneAgent

10d

1B+

28

HARDENED IMAGE
Recommended

The AWS EKS Pod Identity Agent runs on Amazon EKS nodes and exchanges Kubernetes service account tokens for temporary AWS IAM credentials, providing pods with IAM roles without using IRSA or instance profiles.

10h

100K+

HARDENED IMAGE
Recommended

Gitleaks is a SAST tool for detecting and preventing hardcoded secrets like passwords, API keys, and tokens in git repos. Written in Go.

10h

100K+

HARDENED IMAGE
Recommended

cert-manager trust-manager manages trust bundles in Kubernetes and OpenShift clusters

10h

100K+

HARDENED IMAGE
Recommended

Apache APISIX is a dynamic, real-time, high-performance API Gateway.

4h

100K+

HARDENED IMAGE
Recommended

Polaris is an open source policy engine for Kubernetes that validates and remediates resource configuration. It includes 30+ built in configuration policies, as well as the ability to build custom policies with JSON Schema. When run on the command line or as a mutating webhook, Polaris can automatically remediate issues based on policy criteria.

10h

100K+

HARDENED IMAGE
Recommended

A Kubernetes utility to identify optimal resource requests and limits using Vertical Pod Autoscalers.

10h

100K+

image

1m

500M+

9

HARDENED IMAGE
Recommended

EFF's ACME client for obtaining and renewing TLS certificates from Let's Encrypt and any ACME-compatible CA.

10h

100K+

2

HARDENED IMAGE
Recommended

The Kyverno Policy Reporter UI watches for PolicyReport Resources and displays information on a web based UI

10h

100K+

HARDENED IMAGE
Recommended

node-collector gathers file system and process information from Kubernetes cluster nodes for CIS benchmark compliance checking.

10h

100K+

image + 1 more

Please refer to the docker/ucp image for more information

6y

500M+

4