Todas las etiquetas
Etiqueta del catálogo

#compliance

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

44 registros
Con la etiqueta «compliance»Ordenado por índice de salud
Go
89Excelenteíndice de salud
kyverno/kyverno
Unified Policy as Code
Go★ 794019 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
npm · PyPI
88Excelenteíndice de salud
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Python · Svelte · TypeScript★ 426817 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go · npm
87Excelenteíndice de salud
open-Policy-agent/opa
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
Go★ 12K17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm · Go · crates.io
86Excelenteíndice de salud
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 4869↓ 12.3K/mes20 jul 2026
MIT20 jul 2026 · métricas 1.13.0
PyPI · npm
86Excelenteíndice de salud
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.1K↓ 50/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go
85Excelenteíndice de salud
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
85Excelenteíndice de salud
wazuh/wazuh-dashboard-plugins
Plugins for Wazuh Dashboard
TypeScript · JavaScript★ 51717 jul 2026
GPL-2.017 jul 2026 · métricas 1.13.0
Go · npm
81Buenoíndice de salud
getprobo/probo
Open source solutions for SOC2, GDPR, and ISO27001
Go · TypeScript★ 123018 jul 2026
MIT18 jul 2026 · métricas 1.13.0
npm
80Buenoíndice de salud
hack23/cia-compliance-manager
The CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security levels, providing real-time cost estimates, business impact assessments, and technical implementation details.
TypeScript · HTML★ 20↓ 3879/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
RubyGems · Go
80Buenoíndice de salud
inspec/inspec
InSpec: Auditing and Testing Framework
Ruby★ 308219 jul 2026
Licencia propia19 jul 2026 · métricas 1.13.0
PyPI · npm
80Buenoíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
Maven · npm
80Buenoíndice de salud
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 205117 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go
77Buenoíndice de salud
getplumber/plumber
Plumber detects CI/CD security issues in your GitHub workflows and gives you a score
Go★ 75917 jul 2026
MPL-2.017 jul 2026 · métricas 1.13.0
PyPI
73Buenoíndice de salud
datafog/datafog-python
Offline PII firewall for AI agents and LLM apps: fast local detection and redaction, Claude Code hook, LiteLLM guardrail. Zero network calls, one dependency.
Python★ 67↓ 34K/mes16 jul 2026
MIT16 jul 2026 · métricas 1.13.0
72Buenoíndice de salud
Cratis/Chronicle
Event sourcing made easy—no complexity, just powerful tools and flexibility for everyone, from beginners to pros.
C#★ 5617 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Maven · npm
72Buenoíndice de salud
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 6615 jul 2026
Apache-2.015 jul 2026 · métricas 1.13.0
Go
70Buenoíndice de salud
theopenlane/go-client
Openlane go-client, useful for automating your SOC 2 evidence collection, updating ISO27001 controls, or really anything you want to do in the Openlane system
Go★ 516 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
npm
68Moderadoíndice de salud
MarkAC007/mcp-server-scf
MCP server for SCF Controls Platform — security compliance controls, frameworks, evidence, and risk management for AI agents
TypeScript★ 1↓ 3562/mes22 jul 2026
MIT22 jul 2026 · métricas 1.13.0
Packagist
67Moderadoíndice de salud
rcsofttech85/AuditTrailBundle
A Symfony bundle for teams where audit is infrastructure, not just history.
PHP★ 119↓ 7276/mes16 jul 2026
MIT16 jul 2026 · métricas 1.13.0
Go
67Moderadoíndice de salud
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 jul 2026
Apache-2.020 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
had-nu/wardex
Risk-based release gate for CRA (Article 14), NIS2 and DORA compliance with SBOM, KEV correlation, and auditable evidence.
Go★ 220 jul 2026
Licencia propia20 jul 2026 · métricas 1.13.0
npm · Go
65Moderadoíndice de salud
mitre/hdf-libs
Heimdall Data Format (HDF) is a standardized JSON schema for representing security assessment baselines and results across diverse tools and platforms.
Go · TypeScript★ 1↓ 52.8K/mes15 jul 2026
Licencia propia15 jul 2026 · métricas 1.13.0
PyPI
65Moderadoíndice de salud
vaaraio/vaara
Open-source evidence layer for AI governance. Gates every AI agent tool call against your policy and writes a hash-chained execution record an auditor verifies offline, without trusting the operator. Root-agnostic, and binds to a TPM 2.0 or SEV-SNP hardware root when present. Your environment, no SaaS, no telemetry. AGPL-3.0.
Python★ 10↓ 7840/mes14 jul 2026
AGPL-3.014 jul 2026 · métricas 1.13.0
Go
64Moderadoíndice de salud
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 jul 2026
BSD-3-Clause21 jul 2026 · métricas 1.13.0
Go
63Moderadoíndice de salud
alun-hub/sudo-logger
Network dependent Sudo session logger and logplayback GUI
Go★ 0↓ 0/mes14 jul 2026
AGPL-3.014 jul 2026 · métricas 1.13.0
Packagist
62Moderadoíndice de salud
Lendable/composer-license-checker
Tool to check licensing of Composer depdencies against a set of rules to ensure compliance
PHP★ 15↓ 19.4K/mes16 jul 2026
MIT16 jul 2026 · métricas 1.13.0
PyPI
62Moderadoíndice de salud
dgeragh/license-audit
Analyze dependency licenses and get actionable licensing guidance for Python projects.
Python★ 017 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go
62Moderadoíndice de salud
trisacrypto/envoy
An open source TRISA node for use in Travel Rule information transfers
Go · HTML★ 1419 jul 2026
MIT19 jul 2026 · métricas 1.13.0
Go
61Moderadoíndice de salud
djadmin/fort
Audit and fix your Mac's security in one command. No agent, no signup, open source.
Go · HTML★ 72↓ 0/mes14 jul 2026
MIT14 jul 2026 · métricas 1.13.0