Skip to main content
buildradar
Sign in
Topic · compliance

compliance

Tracked open-source repos tagged compliance, sorted by stars.

60 repos
  • databunker@securitybunker

    Secure Vault for Customer PII/PHI/PCI/KYC Records

    1,484+1Star change over the last 7 days
  • lunasec@lunasec-io

    LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

    1,469+0Star change over the last 7 days
  • cli@terraform-compliance

    a lightweight, security focused, BDD test framework against terraform.

    1,462+1Star change over the last 7 days
  • tradememory-protocol@mnemox-ai

    Decision audit trail + persistent memory for AI trading agents. Outcome-weighted recall, tamper-evident SHA-256 chain with RFC 3161 anchoring, 20 MCP tools.

    1,411-1Star change over the last 7 days
  • cloudformation-guard@aws-cloudformation

    Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

    1,386+0Star change over the last 7 days
  • probo@getprobo

    Open source solutions for SOC2, GDPR, and ISO27001

    1,330+10Star change over the last 7 days
  • cfn_nag@stelligent

    Linting tool for CloudFormation templates

    1,308-1Star change over the last 7 days
  • dep-scan@owasp-dep-scan

    OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

    1,282+0Star change over the last 7 days
  • wazuh-docker@wazuh

    Wazuh - Docker containers

    1,173+2Star change over the last 7 days
  • bernstein@sipyourdrink-ltd

    The open‑source AI Agents Governance & Orchestration framework: write the rules declaratively, Bernstein enforces them and produces the verifiable, replayable record. Free, Apache-2.0. https://bernstein.run

    1,120+94Star change over the last 7 days
  • Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

    1,109+3Star change over the last 7 days
  • Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).

    1,086+6Star change over the last 7 days
  • Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container hardening, SOC2/ISO27001, and incident response—plus ready-to-run scripts, templates, and playbooks for SRE, platform, and security teams.

    1,067+215Star change over the last 7 days
  • ElectricEye@jonrau1

    ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

    1,045+0Star change over the last 7 days
  • fossology@fossology

    FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and web ui are provided to give you a compliance workflow. License, copyright and export scanners are tools used in the workflow.

    1,024+3Star change over the last 7 days
  • tern@tern-tools

    Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.

    1,020+2Star change over the last 7 days
  • OSCAL@usnistgov

    Open Security Controls Assessment Language (OSCAL)

    950+5Star change over the last 7 days
  • super@Macjutsu

    S.U.P.E.R.M.A.N. optimizes the macOS software update experience.

    891+1Star change over the last 7 days
  • Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, CCPA/CPRA, and others. Benchmark 93% (with skills) vs 74% (without skills). Updated Monthly.

    886+24Star change over the last 7 days
  • plumber@getplumber

    Plumber detects CI/CD security issues in your GitHub workflows and gives you a score

    790+7Star change over the last 7 days
  • opensecurity@opengovern

    opensecurity: open-source security and compliance. See and secure your cloud, containers, code, networks, deployments, devices. Define your rules, get precise checks, fix gaps fast. Streamlined audits. No fluff.

    717+0Star change over the last 7 days
  • rudder@Normation

    Rudder is a configuration and security automation platform. Manage your Cloud, hybrid or on-premises infrastructure in a simple, scalable and dynamic way.

    707+1Star change over the last 7 days
  • gapps@bmarsh9

    Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

    689+0Star change over the last 7 days
  • privado@Privado-Inc

    Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.

    656+2Star change over the last 7 days
  • marble@checkmarble

    Marble - the real time decision engine for fraud and AML

    597+7Star change over the last 7 days
  • chainloop@chainloop-dev

    SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more

    583+0Star change over the last 7 days
  • UTMStack@utmstack

    Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.

    581+1Star change over the last 7 days
  • binaryanalysis-ng@armijnhemel

    Binary Analysis Next Generation (BANG)

    531+0Star change over the last 7 days
  • Plugins for Wazuh Dashboard

    522+1Star change over the last 7 days
  • Info about many of my Terraform, AWS, DevOps, and AI (tada!) projects.

    505+0Star change over the last 7 days
← Back to topics