Category
Cloud / DevSecOps
Infrastructure-as-code scanning, container and supply-chain checking, and cloud posture auditing — the tooling that sits between a repository and a production account.
Subtopics
The branches this category is organised into. Counts reflect documented entries, not the number of tools that exist.
Infrastructure as Code
1Policy checks for Terraform, CloudFormation and Kubernetes.
Open subtopicContainers & Supply Chain
1Image scanning, provenance and dependency risk.
Open subtopicCloud Posture
0Read-only auditing of account configuration and IAM.
Unfilled — contributeSecrets & Configuration
0Finding credentials and unsafe defaults in code and configs.
Unfilled — contribute
Cloud / DevSecOps tools
Sorted alphabetically; use the directory filters for platform or difficulty narrowing.
- Verified
Checkov
Policy scanning for Terraform, Kubernetes and cloud config
Cloud / DevSecOps·Infrastructure as Code
- Linux
- macOS
- Windows
- Docker
- +1 more
4 commands·Beginner2 Jan 2026 - Verified
Trivy
Scanner for containers, filesystems, repos and cloud config
Cloud / DevSecOps·Containers & Supply Chain
- Linux
- macOS
- Windows
- Docker
- +1 more
5 commands·Beginner1 Jan 2026