全部标签
目录标签

#compliance

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

45 条记录
标签为“compliance”按健康指数排序
Go
89优秀健康指数
kyverno/kyverno
Unified Policy as Code
Go★ 7,9402026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
npm · PyPI
88优秀健康指数
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Python · Svelte · TypeScript★ 4,2682026年7月17日
自定义许可证2026年7月17日 · 指标 1.13.0
Go · npm
87优秀健康指数
open-Policy-agent/opa
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
Go★ 12K2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
npm · Go · crates.io
86优秀健康指数
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 4,869↓ 12.3K/月2026年7月20日
MIT2026年7月20日 · 指标 1.13.0
PyPI · npm
86优秀健康指数
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.1K↓ 50/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Go
85优秀健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
85优秀健康指数
wazuh/wazuh-dashboard-plugins
Plugins for Wazuh Dashboard
TypeScript · JavaScript★ 5172026年7月17日
GPL-2.02026年7月17日 · 指标 1.13.0
Go · npm
81良好健康指数
getprobo/probo
Open source solutions for SOC2, GDPR, and ISO27001
Go · TypeScript★ 1,2302026年7月18日
MIT2026年7月18日 · 指标 1.13.0
npm
80良好健康指数
hack23/cia-compliance-manager
The CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security levels, providing real-time cost estimates, business impact assessments, and technical implementation details.
TypeScript · HTML★ 20↓ 3,879/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
RubyGems · Go
80良好健康指数
inspec/inspec
InSpec: Auditing and Testing Framework
Ruby★ 3,0822026年7月19日
自定义许可证2026年7月19日 · 指标 1.13.0
PyPI · npm
80良好健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
Maven · npm
80良好健康指数
oss-review-toolkit/ort
A suite of tools to automate software compliance checks.
Kotlin★ 2,0512026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Go
77良好健康指数
getplumber/plumber
Plumber detects CI/CD security issues in your GitHub workflows and gives you a score
Go★ 7592026年7月17日
MPL-2.02026年7月17日 · 指标 1.13.0
PyPI
73良好健康指数
datafog/datafog-python
Offline PII firewall for AI agents and LLM apps: fast local detection and redaction, Claude Code hook, LiteLLM guardrail. Zero network calls, one dependency.
Python★ 67↓ 34K/月2026年7月16日
MIT2026年7月16日 · 指标 1.13.0
72良好健康指数
Cratis/Chronicle
Event sourcing made easy—no complexity, just powerful tools and flexibility for everyone, from beginners to pros.
C#★ 562026年7月17日
MIT2026年7月17日 · 指标 1.13.0
Maven · npm
72良好健康指数
eclipse-apoapsis/ort-server
A scalable server implementation of the OSS Review Toolkit.
Kotlin · TypeScript★ 662026年7月15日
Apache-2.02026年7月15日 · 指标 1.13.0
Go
70良好健康指数
theopenlane/go-client
Openlane go-client, useful for automating your SOC 2 evidence collection, updating ISO27001 controls, or really anything you want to do in the Openlane system
Go★ 52026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
npm
68中等健康指数
MarkAC007/mcp-server-scf
MCP server for SCF Controls Platform — security compliance controls, frameworks, evidence, and risk management for AI agents
TypeScript★ 1↓ 3,562/月2026年7月22日
MIT2026年7月22日 · 指标 1.13.0
Go
68中等健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月23日
Apache-2.02026年7月23日 · 指标 1.13.0
PyPI
67中等健康指数
ethanolivertroy/wilma
Wilma - AWS Bedrock Security Configuration Checker
Python★ 32026年7月23日
GPL-3.02026年7月23日 · 指标 1.13.0
Packagist
67中等健康指数
rcsofttech85/AuditTrailBundle
A Symfony bundle for teams where audit is infrastructure, not just history.
PHP★ 119↓ 7,276/月2026年7月16日
MIT2026年7月16日 · 指标 1.13.0
Go
67中等健康指数
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 242026年7月20日
Apache-2.02026年7月20日 · 指标 1.13.0
Go
66中等健康指数
had-nu/wardex
Risk-based release gate for CRA (Article 14), NIS2 and DORA compliance with SBOM, KEV correlation, and auditable evidence.
Go★ 22026年7月20日
自定义许可证2026年7月20日 · 指标 1.13.0
npm · Go
65中等健康指数
mitre/hdf-libs
Heimdall Data Format (HDF) is a standardized JSON schema for representing security assessment baselines and results across diverse tools and platforms.
Go · TypeScript★ 1↓ 52.8K/月2026年7月15日
自定义许可证2026年7月15日 · 指标 1.13.0
PyPI
65中等健康指数
vaaraio/vaara
Open-source evidence layer for AI governance. Gates every AI agent tool call against your policy and writes a hash-chained execution record an auditor verifies offline, without trusting the operator. Root-agnostic, and binds to a TPM 2.0 or SEV-SNP hardware root when present. Your environment, no SaaS, no telemetry. AGPL-3.0.
Python★ 10↓ 7,840/月2026年7月14日
AGPL-3.02026年7月14日 · 指标 1.13.0
Go
64中等健康指数
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 22026年7月21日
BSD-3-Clause2026年7月21日 · 指标 1.13.0
Go
63中等健康指数
alun-hub/sudo-logger
Network dependent Sudo session logger and logplayback GUI
Go★ 0↓ 0/月2026年7月14日
AGPL-3.02026年7月14日 · 指标 1.13.0
Packagist
62中等健康指数
Lendable/composer-license-checker
Tool to check licensing of Composer depdencies against a set of rules to ensure compliance
PHP★ 15↓ 19.4K/月2026年7月16日
MIT2026年7月16日 · 指标 1.13.0
PyPI
62中等健康指数
dgeragh/license-audit
Analyze dependency licenses and get actionable licensing guidance for Python projects.
Python★ 02026年7月17日
MIT2026年7月17日 · 指标 1.13.0
Go
62中等健康指数
trisacrypto/envoy
An open source TRISA node for use in Travel Rule information transfers
Go · HTML★ 142026年7月19日
MIT2026年7月19日 · 指标 1.13.0