All tags
Catalogue tag

#compliance

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

44 records
Tagged “compliance”Ranked by health index
Go
89Excellenthealth index
kyverno/kyverno
Unified Policy as Code
Go★ 7,940Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0
npm · PyPI
88Excellenthealth index
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Python · Svelte · TypeScript★ 4,268Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
Go · npm
87Excellenthealth index
open-Policy-agent/opa
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
Go★ 12KJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm · Go · crates.io
86Excellenthealth index
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 4,869↓ 12.3K/moJul 20, 2026
MITJul 20, 2026 · metrics 1.13.0
PyPI · npm
86Excellenthealth index
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.1K↓ 50/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
Go
85Excellenthealth index
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 570Jul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
85Excellenthealth index
wazuh/wazuh-dashboard-plugins
Plugins for Wazuh Dashboard
TypeScript · JavaScript★ 517Jul 17, 2026
GPL-2.0Jul 17, 2026 · metrics 1.13.0
Go · npm
81Goodhealth index
getprobo/probo
Open source solutions for SOC2, GDPR, and ISO27001
Go · TypeScript★ 1,230Jul 18, 2026
MITJul 18, 2026 · metrics 1.13.0
npm
80Goodhealth index
hack23/cia-compliance-manager
The CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security levels, providing real-time cost estimates, business impact assessments, and technical implementation details.
TypeScript · HTML★ 20↓ 3,879/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
RubyGems · Go
80Goodhealth index
inspec/inspec
InSpec: Auditing and Testing Framework
Ruby★ 3,082Jul 19, 2026
Custom licenseJul 19, 2026 · metrics 1.13.0
PyPI · npm
80Goodhealth index
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
Maven · npm
80Goodhealth index
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 2,051Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
Go
77Goodhealth index
getplumber/plumber
Plumber detects CI/CD security issues in your GitHub workflows and gives you a score
Go★ 759Jul 17, 2026
MPL-2.0Jul 17, 2026 · metrics 1.13.0
PyPI
73Goodhealth index
datafog/datafog-python
Offline PII firewall for AI agents and LLM apps: fast local detection and redaction, Claude Code hook, LiteLLM guardrail. Zero network calls, one dependency.
Python★ 67↓ 34K/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
72Goodhealth index
Cratis/Chronicle
Event sourcing made easy—no complexity, just powerful tools and flexibility for everyone, from beginners to pros.
C#★ 56Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Maven · npm
72Goodhealth index
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 66Jul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 1.13.0
Go
70Goodhealth index
theopenlane/go-client
Openlane go-client, useful for automating your SOC 2 evidence collection, updating ISO27001 controls, or really anything you want to do in the Openlane system
Go★ 5Jul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
npm
68Moderatehealth index
MarkAC007/mcp-server-scf
MCP server for SCF Controls Platform — security compliance controls, frameworks, evidence, and risk management for AI agents
TypeScript★ 1↓ 3,562/moJul 22, 2026
MITJul 22, 2026 · metrics 1.13.0
Packagist
67Moderatehealth index
rcsofttech85/AuditTrailBundle
A Symfony bundle for teams where audit is infrastructure, not just history.
PHP★ 119↓ 7,276/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
Go
67Moderatehealth index
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 24Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 1.13.0
Go
66Moderatehealth index
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
Go
66Moderatehealth index
had-nu/wardex
Risk-based release gate for CRA (Article 14), NIS2 and DORA compliance with SBOM, KEV correlation, and auditable evidence.
Go★ 2Jul 20, 2026
Custom licenseJul 20, 2026 · metrics 1.13.0
npm · Go
65Moderatehealth index
mitre/hdf-libs
Heimdall Data Format (HDF) is a standardized JSON schema for representing security assessment baselines and results across diverse tools and platforms.
Go · TypeScript★ 1↓ 52.8K/moJul 15, 2026
Custom licenseJul 15, 2026 · metrics 1.13.0
PyPI
65Moderatehealth index
vaaraio/vaara
Open-source evidence layer for AI governance. Gates every AI agent tool call against your policy and writes a hash-chained execution record an auditor verifies offline, without trusting the operator. Root-agnostic, and binds to a TPM 2.0 or SEV-SNP hardware root when present. Your environment, no SaaS, no telemetry. AGPL-3.0.
Python★ 10↓ 7,840/moJul 14, 2026
AGPL-3.0Jul 14, 2026 · metrics 1.13.0
Go
64Moderatehealth index
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 2Jul 21, 2026
BSD-3-ClauseJul 21, 2026 · metrics 1.13.0
Go
63Moderatehealth index
alun-hub/sudo-logger
Network dependent Sudo session logger and logplayback GUI
Go★ 0↓ 0/moJul 14, 2026
AGPL-3.0Jul 14, 2026 · metrics 1.13.0
Packagist
62Moderatehealth index
Lendable/composer-license-checker
Tool to check licensing of Composer depdencies against a set of rules to ensure compliance
PHP★ 15↓ 19.4K/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
PyPI
62Moderatehealth index
dgeragh/license-audit
Analyze dependency licenses and get actionable licensing guidance for Python projects.
Python★ 0Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go
62Moderatehealth index
trisacrypto/envoy
An open source TRISA node for use in Travel Rule information transfers
Go · HTML★ 14Jul 19, 2026
MITJul 19, 2026 · metrics 1.13.0
Go
61Moderatehealth index
djadmin/fort
Audit and fix your Mac's security in one command. No agent, no signup, open source.
Go · HTML★ 72↓ 0/moJul 14, 2026
MITJul 14, 2026 · metrics 1.13.0