Skip to content

Latest commit

 

History

History
126 lines (126 loc) · 99.5 KB

oss_projects_tracked.md

File metadata and controls

126 lines (126 loc) · 99.5 KB
Open Source Project Type
Sl.No Be-Secure open source security tech stack Sub- category Name Description Main GitHub repo License Language Foundation led projects Community led projects Technology Composition Industry Technology Domain (Usage) Security Domain Core Security Theme Use Case
1 DO Monitoring Prometheus It is a Cloud Native Computing Foundation project, is a systems and service monitoring system. It collects metrics from configured targets at given intervals, evaluates rule expressions, displays the results, and can trigger alerts when specified conditions are observed. https://github.com/prometheus/prometheus Apache-2.0 Go CNCF All Msg SOC
2 DO Monitoring DefectDojo It is an open-source application vulnerability correlation and security orchestration tool. https://github.com/DefectDojo/django-DefectDojo BSD-3.0 HTML, Python OWASP All Msg SOC CR
3 DO Monitoring Hygieia CapitalOne DevOps Dashboard https://github.com/hygieia/hygieia Apache-2.0 TypeScript, HTML Hygieia All Msg CR
4 DO Monitoring Grafana The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more https://github.com/grafana/grafana AGPL-3.0 TypeScript, Go GrafanaLabs All Msg SOC CR
5 DO Monitoring Kafka Apache Kafka is an open-source distributed event streaming platform used for high-performance data pipelines, streaming analytics, data integration, and mission-critical applications. https://github.com/apache/kafka Apache-2.0 Java, Scala Kafka All Msg SOC
6 DO Messaging RabbitMQ server RabbitMQ is a feature rich, multi-protocol messaging broker https://github.com/rabbitmq/rabbitmq-server MPL-2.0 Shell, Makefile VMWare All Msg
7 DO Code Generator Captain Stack VSCode extension for code suggestion https://github.com/hieunc229/copilot-clone MIT JavaScript, TypeScript All W
8 DO Code Generator Gpt-code-clippy It is an open source version of GitHub Copilot https://github.com/ncoop57/gpt-code-clippy Apache-2.0 Python All W
9 DO Code Generator Secondmate An open-source, mini imitation of GitHub Copilot for Emacs https://github.com/samrawal/emacs-secondmate Apache-2.0 Python, emacs lisp All W
10 DO IaC Checkov It is a static code analysis tool for infrastructure-as-code.It scans cloud infrastructure provisioned using Terraform, Terraform plan, Cloudformation, Kubernetes, Dockerfile, Serverless or ARM Templates and detects security and compliance misconfigurations using graph-based scanning https://github.com/bridgecrewio/checkov Apache-2.0 Python BridgeCrew All CR
11 DO Ansible Ansistrano (Ansible) ansistrano.deploy and ansistrano.rollback are Ansible roles to easily manage the deployment process for scripting applications such as PHP, Python and Ruby https://github.com/ansistrano/deploy MIT YAML Ansistrano All
12 DO Ansible Trellis (Ansible) Ansible playbooks for a WordPress LEMP stack https://github.com/roots/trellis MIT Jinja, Python Roots All
13 DO Ansible Molecule (Ansible) Molecule aids in the development and testing of Ansible roles https://github.com/ansible-community/molecule MIT Python Red Hat All
14 DO Kubernetes Minikube (Kubernetes) minikube implements a local Kubernetes cluster on macOS, Linux, and Windows. minikube's primary goals are to be the best tool for local Kubernetes application development and to support A Kubernetes features that fit https://github.com/kubernetes/minikube Apache-2.0 Go, HTML minikube All
15 DO Kubernetes Helm (Kubernetes) Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources https://github.com/helm/helm Apache-2.0 Go CNCF All
16 DO Kubernetes PowerfulSeal (Kubernetes) PowerfulSeal injects failure into your Kubernetes clusters, so that you can detect problems as early as possible. It Aows for writing scenarios describing complete chaos experiments https://github.com/powerfulseal/powerfulseal Apache-2.0 Python TheLinux Foundation All SC
17 L&F Pattern Generation Tensorflow An Open Source Machine Learning Framework for Everyone https://github.com/tensorflow/tensorflow Apache-2.0 C++, Python TensorFlow All ML
18 L&F Pattern Generation Pykale Knowledge-Aware machine LEarning (KALE) from multiple sources in Python https://github.com/pykale/pykale MIT Python **University of Sheffield All ML
19 L&F Content Management Wagtail (Python-Django) It is an open source content management system built on Django, with a strong community and commercial support. It's focused on user experience, and offers precise control for designers and developers https://github.com/wagtail/wagtail BSD-3 Python, HTML TorchBox CON / NG / ED DkA
20 L&F eCommerce Saleor (Python-Django) A headless, GraphQL commerce platform delivering ultra-fast, dynamic, personalized shopping experiences https://github.com/mirumee/saleor BSD-3 Python Mirumee Labs CON W
21 L&F Monitoring Healthchecks (Python-Django) It is a cron job monitoring service. It listens for HTTP requests and email messages ("pings") from your cron jobs and scheduled tasks ("checks"). When a ping does not arrive on time, Healthchecks sends out alerts https://github.com/healthchecks/healthchecks BSD-3 Python, HTML SIA Monkey See Monkey Do *** All Msg
22 L&F Web Application Spring-security (Java-Spring) Spring Security provides security services for the Spring IO Platform https://github.com/spring-projects/spring-security Apache-2.0 Java All W
23 L&F Web Application Springfox (Java-Spring) Automated JSON API documentation for API's built with Spring https://github.com/springfox/springfox Apache-2.0 Java, Groovy SpringFox All ApD
24 L&F Web Application Dispora (Ruby-Rails) A privacy-aware, distributed, open source social network https://github.com/diaspora/diaspora GNU GPL Ruby, JavaScript Diaspora All W
25 L&F Web Application Chatwoot (Ruby- Rails) It is an open-source omnichannel customer support software https://github.com/chatwoot/chatwoot MIT Ruby, Vue Chatwoot All W
26 L&F Infra Portus (Ruby-Rails) It is an authorization server and a user interface for the next generation of the Docker registry. Portus targets version 2 of the Docker Registry API https://github.com/SUSE/Portus Apache-2.0 Ruby, Vue SUSE All
27 L&F Infra PHP-PM (PHP-Symfony) It is a process manager, superchargerand load balancer for PHP applications https://github.com/php-pm/php-pm MIT PHP All
28 L&F Web Application Grav (PHP-Symfony) It is a Fast, Simple, and Flexible, file-based Web-platform https://github.com/getgrav/grav MIT PHP Grav All W
29 L&F Web Application Akaunting Free and Online Accounting Software https://github.com/akaunting/akaunting GPL-3.0 PHP, Blade akaunting BFSI / NG W
30 L&F Web Application Wallabag (PHP-Symfony) It is a self-hostable PHP application allowing you to not miss any content anymore. Click, save and read it when you can. It extracts content so that you can read it when you have time https://github.com/wallabag/wallabag MIT PHP, Twig wallabag All W
31 L&F Web Application Hexo (NodeJS) A fast, simple & powerful blog framework, powered by Node.js https://github.com/hexojs/hexo MIT JavaScript hexo All W
32 L&F Web Application Joplin (NodeJS) It is an open source note taking and to-do application with synchronization capabilities for Windows, macOS, Linux, Android and iOS. https://github.com/laurent22/joplin MIT TypeScript, JavaScript Joplin All W
33 L&F Web Application Bit (TypeScript) A tool for component-driven application development https://github.com/teambit/bit Apache-2.0 TypeScript All W
34 L&F Web Application Koha Koha is a free software integrated library system (ILS) https://github.com/Koha-Community/Koha GPL-3.0 Perl, JavaScript Koha NG W
35 A Enterprise Platform Espocrm EspoCRM open source CRM application https://github.com/espocrm/espocrm GPL-3.0 PHP, JavaScript espocrm All DkA
36 A Enterprise Platform Pimcore Open Source Data & Experience Management Platform (PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce) https://github.com/pimcore/pimcore GPL-3.0 PHP, JavaScript pimcore All DkA
37 DA App Fabric It is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. Its modular and versatile design satisfies a broad range of industry use cases. It offers a unique approach to consensus that enables performance at scale while preserving privacy. https://github.com/hyperledger/fabric Apache-2.0 Go Hyperledger All
38 DA App Indy-sdk This is the official SDK for Hyperledger Indy, which provides a distributed-ledger-based foundation for self-sovereign identity. https://github.com/hyperledger/indy-sdk Apache-2.0 Rust, Java, Python Hyperledger All
39 DA App Sawtooth Hyperledger Sawtooth is an enterprise solution for building, deploying, and running distributed ledgers (also called blockchains). It provides an extremely modular and flexible platform for implementing transaction-based updates to shared state between untrusted parties coordinated by consensus algorithms. https://github.com/hyperledger/sawtooth-core Apache-2.0 Python, Rust, Shell Hyperledger All
40 DA App Aries Hyperledger Aries is infrastructure for blockchain-rooted, peer-to-peer interactions https://github.com/hyperledger/aries Apache-2.0 Python, Shell, JavaScript Hyperledger All
41 DA App Caliper A blockchain benchmark framework to measure performance of multiple blockchain solutions https://github.com/hyperledger/caliper Apache-2.0 JavaScript Hyperledger All
42 DA App Burrow Hyperledger Burrow is a permissioned Ethereum smart-contract blockchain node. https://github.com/hyperledger/burrow Apache-2.0 Go Hyperledger All
43 DA App Besu An enterprise-grade Java-based, Apache 2.0 licensed Ethereum client https://github.com/hyperledger/besu Apache-2.0 Java Hyperledger All
44 DA App Iroha A simple, enterprise-grade decentralized ledger https://github.com/hyperledger/iroha Apache-2.0 C++ Hyperledger All
45 DA App Cactus Hyperledger Cactus is a new approach to the blockchain interoperability problem https://github.com/hyperledger/cactus Apache-2.0 TypeScript, JavaScript Hyperledger All
46 DA ?? Cello Operating System for Enterprise Blockchain https://github.com/hyperledger/cello Apache-2.0 Python, JavaScript Hyperledger All
47 DA Library Ursa Hyperledger Ursa is a shared cryptography library https://github.com/hyperledger/ursa Apache-2.0 Rust Hyperledger All
48 DA Library Differential-privacy Google's differential privacy libraries. https://github.com/google/differential-privacy Apache-2.0 C++, Go, Java Google All ZT
49 S Tool ModSecurity It is is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis. https://github.com/SpiderLabs/ModSecurity Apache-2.0 C++ Trustwave All W IS CR
50 S Tool Threat-dragon An open source, online threat modeling tool from OWASP https://github.com/OWASP/threat-dragon Apache-2.0 JavaScript, HTML OWASP All SRM CR. SC
51 S App Archery-sec Centralize Vulnerability Assessment and Management for DevSecOps Team https://github.com/archerysec/archerysec GPL-3.0 JavaScript, Python, HTML Archery All AS CR
52 S App Anchore-engine A service that analyzes docker images and applies user-defined acceptance policies to allow automated container image validation and certification https://github.com/anchore/anchore-engine Apache-2.0 Python Anchore All AS CR, SC
53 S Tool Clair Vulnerability Static Analysis for Containers https://github.com/quay/clair Apache-2.0 Go Quay All AS CR, SC
54 S Tool Trivy Scanner for vulnerabilities in container images, file systems, and Git repositories, as well as for configuration issues https://github.com/aquasecurity/trivy Apache-2.0 Go Aqua Security All AS CR, SC
55 S Tool CS-suite Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure https://github.com/SecurityFTW/cs-suite GPL-3.0 Shell, Python All CS SC
56 S Tool Alerta Alerta monitoring system https://github.com/alerta/alerta Apache-2.0 Python All SOC CR
57 S Tool Glue Application Security Automation https://github.com/OWASP/glue Apache-2.0 Ruby OWASP All AS CR
58 S Tool Openscap NIST Certified SCAP 1.2 toolkit https://github.com/OpenSCAP/openscap LGPL-2.1 XSLT, C OpenSCAP All SRM CR
59 S Tool Fuzzbench FuzzBench - Fuzzer benchmarking as a service. https://github.com/google/fuzzbench Apache-2.0 Python, Jupyter Noebook google All AS CR
60 S Tool Ghidra Ghidra is a software reverse engineering (SRE) framework https://github.com/NationalSecurityAgency/ghidra Apache-2.0 Java NSA All AS CR, TPR
61 S Tool Apache syncope Apache Syncope https://github.com/apache/syncope Apache-2.0 Java Apache All AS DT
62 S Tool Pritunl-zero It is a zero trust system that provides secure authenticated access to internal services from untrusted networks without the use of a VPN. https://github.com/pritunl/pritunl-zero Non commercial Go, TypeScript, Pritunl All W IAM ZT, DT
63 S Tool Pacu The AWS exploitation framework, designed for testing the security of Amazon Web Services environments https://github.com/RhinoSecurityLabs/pacu BSD-3.0 Python Rhino Security Labs All CS SC
64 S Tool Nmap This is the Network Mapper https://github.com/nmap/nmap Nmap PSL - 0.93 Lua, C, C++ Nmap All NS OTS
65 S Tool Trasa Zero Trust Service Access https://github.com/seknox/trasa MPL-2.0 Go, TypeScript, JavaScript Trasa All W IAM ZT
66 S Language Kestrel-lang Kestrel Threat Hunting Language https://github.com/opencybersecurityalliance/kestrel-lang Apache-2.0 Python OCA All SRM CR, SC, OTS
67 S Tool Snort3 Snort 3 is the next generation Snort IPS (Intrusion Prevention System) https://github.com/snort3/snort3 GNU GPL-2.0 C++ Snort All NS, SOC OTS
68 S Tool Cset Cybersecurity Evaluation Tool https://github.com/cisagov/cset MIT TSQL, HTML CISA All AS CR
69 S Standard Stix-shifter This project consists of an open source library allowing software to connect to data repositories using STIX Patterning, and return results as STIX Observations. https://github.com/opencybersecurityalliance/stix-shifter Apache-2.0 Python OCA All SRM CR
70 S Tool Malcolm Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files) and Zeek logs https://github.com/cisagov/Malcolm Python, Shell, CSS, Zeek CISA All NS OTS
71 S Tool Ossec-hids OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. https://github.com/ossec/ossec-hids GNU GPL-2.0 C, AtomiCorp All NS SC
72 S Tool Zeek Zeek is a powerful network analysis framework https://github.com/zeek/zeek C++, Zeek Zeek All NS OTS
73 S Tool Securityonion Security Onion 2 - Linux distro for threat hunting, enterprise security monitoring, and log management https://github.com/Security-Onion-Solutions/securityonion Shell, SaltStack Security Onion Solutions All IoTS OTS
74 S Tool Patton The clever vulnerability dependency finder https://github.com/BBVA/patton Apache-2.0 Gherkin, Go, Shell OWASP All AS CR
75 S Tool Opencti OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. https://github.com/OpenCTI-Platform/opencti Apache-2.0 JavaScript French National Cybersecurity Agency, CERT-EU & Luatix All SRM CR
76 S Tool Croc It is a tool that allows any two computers to simply and securely transfer files and folders https://github.com/schollz/croc MIT Go, Shell Digital Ocean All IS OTS
77 S Standard Opendxl-ontology The OpenDXL Ontology project is focused on the development of an open and interoperable cybersecurity messaging format for use with the OpenDXL messaging bus https://github.com/opencybersecurityalliance/opendxl-ontology Apache-2.0 Shell, Python, Dockerfile OCA All SRM OTS
78 S Tool Security Monkey Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time. https://github.com/Netflix/security_monkey Apache-2.0 Python Netflix All CS SC
79 S Tool Scorecard Security Scorecards - Security health metrics for Open Source https://github.com/ossf/scorecard Apache-2.0 Go OSSF All AS CR, SC
80 S Tool Emmy Library for zero-knowledge proof based applications (like anonymous credentials) https://github.com/xlab-si/emmy Apache-2.0 Go Xlab All W IAM ZT
81 S Tool Grype A vulnerability scanner for container images and filesystems https://github.com/anchore/grype Apache-2.0 Go Anchore All AS CR, SC
82 S Tool Syft CLI tool and library for generating a Software Bill of Materials from container images and filesystems https://github.com/anchore/syft Apache-2.0 Go Anchore All AS CR
83 S Tool Beef The Browser Exploitation Framework Project https://github.com/beefproject/beef JavaScript, Ruby All AS CR
84 S Tool Zaproxy The OWASP ZAP core project https://github.com/zaproxy/zaproxy Apache-2.0 Java, HTML OWASP All AS CR
85 S Tool Jackhammer Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems. https://github.com/olacabs/jackhammer Apache-2.0 Java Olacabs All AS
86 S Tool Openc2-lycan-python OASIS TC Open Repository: A GitHub public repository for development of a python library to transform between data-interchange formats (such as JSON) and python language objects https://github.com/oasis-open/openc2-lycan-python MIT Python OCA All DS
87 S Tool Openc2-jadn-software OASIS TC Open Repository: Development and maintenance of JADN (JSON Abstract Data Notation), a JSON document format for defining abstract schemas. https://github.com/oasis-open/openc2-jadn-software Apache-2.0 Python OCA All DS
88 S Tool Openc2-oif-orchestrator OASIS TC Open Repository: Supports development OpenC2 Integration Framework (OIF) Orchestrator https://github.com/oasis-open/openc2-oif-orchestrator Apache-2.0 Python, JavaScript OCA All DS
89 S Tool TheHive It is a Scalable, Open Source and Free Security Incident Response Platform https://github.com/thehive-project/thehive AGPL-3.0 Scala, JavaScript, HTML All SOC
90 S Tool Shuffle A general purpose security automation platform platform. We focus on accessibility for all. https://github.com/frikky/shuffle AGPL-3.0 JavaScript, Go, Python, HTML All AS CR
91 S Tool WALKOFF A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down. https://github.com/nsacyber/WALKOFF CCO 1.0 Python, TypeScript, Powershell WalkOff All AS
92 S Framework Lockdoor-Framework A Penetration Testing framework with Cyber Security Resources https://github.com/sofianehamlaoui/lockdoor-framework AGPL-3.0 Python, Lex, Shell All AS
93 S Tool Govready-q An open source, self-service GRC tool to automate security assessments and compliance. https://github.com/GovReady/govready-q GPL-3.0 HTML, Python All SRM TPR
94 A IoT platform Kaa Kaa Internet of Things platform for device management, data collection, analytics and visualization, remote control, software updates https://github.com/kaaproject/kaa Kaaproject I IoTS OTS
95 A IoT OS ROS The Robot Operating System - Core ROS packages https://github.com/ros/ros BSD-3 Python, Cmake AM IoTS OTS
96 S Framework Osmedeus Fully automated offensive security framework for reconnaissance and vulnerability scanning https://github.com/j3ssie/Osmedeus MIT Python All SOC CR
97 S Tool Phpcs-security-audit phpcs-security-audit is a set of PHP_CodeSniffer rules that finds vulnerabilities and weaknesses related to security in PHP code https://github.com/FloeDesignTechnologies/phpcs-security-audit GPL-3.0 PHP All AS CR
98 S Tool Codeql-container Prepackaged and precompiled github codeql container for rapid analysis, deployment and development. https://github.com/microsoft/codeql-container MIT Python, Shell All AS CR
99 S Tool asciinema Terminal session recorder https://github.com/asciinema/asciinema GPL-3.0 Python W
100 L&F Pattern Generation Pytorch Tensors and Dynamic neural networks in Python with strong GPU acceleration https://github.com/pytorch/pytorch Copyright C++, Python BFSI ML
101 L&F Database Mongo DB The MongoDB Database https://github.com/mongodb/mongo SSPL C++, JavaScript Mongo DB All D
102 L&F Database CouchDB Seamless multi-master syncing database with an intuitive HTTP/JSON API, designed for reliability https://github.com/apache/couchdb Apache-2.0 Erlang, Elixir Apache All D
103 S Tool Mythril Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Hedera, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains. https://github.com/ConsenSys/mythril MIT Python Mythril All W B ZT
104 S Tool Oyente An Analysis Tool for Smart Contracts https://github.com/enzymefinance/oyente GPL-3.0 JavaScript All W B ZT
105 A Mobile App Canvas-android Canvas Android apps https://github.com/instructure/canvas-android Apache-2.0 Kotlin, Dart All MoA
106 A Enterprise Platform FarmOS GNU GPL-2.0 PHP, YAML All W
107 A Enterprise Platform Canvas-LMS The open LMS by Instructure, Inc. https://github.com/instructure/canvas-lms GPL-3.0 Ruby, JavaScript All W
108 A Enterprise Platform Magento2 A cutting-edge, feature-rich eCommerce solution https://github.com/magento/magento2 OSL-3.0 PHP All W
109 A Enterprise Platform Odoo Odoo is a suite of web based open source business apps https://github.com/odoo/odoo GPL-3.0 JavaScript, Python All W
110 A Enterprise Platform OpenCV Open Source Computer Vision Library https://github.com/opencv/opencv Apache-2.0 C++ All W
111 A Enterprise Platform Moodle Open source learning platform GPL-3.0 PHP, JavaScript All W
112 S Tool Mirswamp The Software Assurance Marketplace (SWAMP) is a platform for running software assurance tools on your code https://github.com/mirswamp/deployment Apache-2.0 Python, HTML, Shell All W AS CR
113 S Tool Trillian A transparent, highly scalable and cryptographically verifiable data store https://github.com/google/trillian Apache-2.0 Go Google All D B CR
114 A IoT OS Tock A secure embedded operating system for microcontrollers https://github.com/tock/tock Apache-2.0 Rust AM, I IoTS OTS
115 A Embedded App Rdkcrytoapi Contains Cryptographic APIs used in the RDK Software Stack https://github.com/rdkcentral/rdkcryptoapi Apache-2.0 C I
116 A Embedded App Lightning Lightning - The WPE UI Framework for developing Apps and UX https://github.com/rdkcentral/Lightning Apache-2.0 JavaScript I
117 A Embedded App Rdkservices RDK Services https://github.com/rdkcentral/rdkservices Apache-2.0 C++ RDK I
118 A Embedded App Ros_comm ROS communications-related packages, including core client libraries (roscpp, rospy, roslisp) and graph introspection tools (rostopic, rosnode, rosservice, rosparam). https://github.com/ros/ros_comm Python, C++ I
119 A Embedded App Meta-ros OpenEmbedded Layers for ROS 1 and ROS 2 https://github.com/ros/meta-ros MIT BitBake, NASL I
120 A Embedded App Catkin A CMake-based build system that is used to build all packages in ROS. https://github.com/ros/catkin BSD-3 Python, CMake I
121 A Embedded App Rosdistro This repo maintains a lists of repositories for each ROS distribution https://github.com/ros/rosdistro BSD Python I
122 A Embedded App Ros_tutorials Code used in tutorials found on ROS wiki https://github.com/ros/ros_tutorials C++, Python I
123 A Embedded App Swig-wx Custom version of swig for wxPython, used by rx https://github.com/ros/swig-wx Copyright C++, C I