kubescape/kubescape

Description: Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and...

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 3 hours ago
Added to GitGenius on June 22nd, 2026
Created on August 12th, 2021
Open Issues & Pull Requests: 63 (+0)
Number of forks: 955
Total Stargazers: 11,541 (+0)
Total Subscribers: 95 (+0)

Issue Activity (beta)

Open issues: 39
New in 7 days: 11
Closed in 7 days: 8
Avg open age: 316 days
Stale 30+ days: 27
Stale 90+ days: 6

Recent activity

Opened in 7 days: 10
Closed in 7 days: 6
Comments in 7 days: 10
Events in 7 days: 33

Top labels

  • bug (128)
  • feature (58)
  • good first issue (7)
  • help wanted (4)
  • backlog (3)
  • documentation (3)
  • to_archive (3)
  • wontfix (3)

Repository Insights (GitGenius)

Median issue/PR response: 0.0 hours
Mean response time: 6.6 hours
90th percentile: 10.7 hours
Tracked items: 282

Most active contributors

Detailed Description

Kubescape is an open-source Kubernetes security platform written in Go that provides comprehensive security coverage across the entire development and deployment lifecycle. Created by ARMO and designated as a Cloud Native Computing Foundation incubating project, it serves as a unified tool for scanning clusters, configuration files, and container images against multiple security frameworks and compliance standards.

The platform offers misconfiguration scanning that evaluates Kubernetes resources against NSA-CISA guidelines, MITRE ATT&CK frameworks, and CIS Benchmarks. Beyond configuration analysis, Kubescape integrates image vulnerability scanning using Grype to detect CVEs in container images, with the capability to automatically patch vulnerable images through Copacetic. The tool includes auto-remediation functionality to automatically fix misconfigurations in Kubernetes manifests and supports enforcement of security policies through Validating Admission Policies. Runtime security monitoring is provided via eBPF-based analysis through Inspektor Gadget, and the platform includes an MCP server for integration with AI assistants.

Kubescape operates in two distinct modes. The CLI mode functions as a standalone tool for on-demand scanning of clusters, files, and images, leveraging Open Policy Agent for policy evaluation and the Regolibrary for security controls. The operator mode deploys as an in-cluster component via Helm to provide continuous security monitoring, including ongoing misconfiguration scanning, image vulnerability detection, runtime threat analysis, and automatic network policy generation with Prometheus metrics integration.

The repository demonstrates active maintenance and community engagement. GitGenius activity tracking shows a median issue and pull request response latency of 0.0 hours with a mean of 6.6 hours across 265 tracked items, indicating rapid triage and response. The most active contributor, matthyx, has logged 526 events, followed by yugal07 with 71 events and slashben with 46 events. Bug reports constitute the most active issue category with 126 items, followed by feature requests with 52 items and good first issues with 7 items, suggesting an accessible entry point for new contributors.

The tool integrates extensively into development workflows through GitHub Actions, GitLab CI, and Jenkins for CI/CD pipeline integration, while IDE extensions exist for VS Code and Lens to enable security scanning during development. Installation is available through multiple package managers including Homebrew, Krew, Arch Linux repositories, Ubuntu PPA, NixOS, Chocolatey, and Scoop, with dedicated Windows PowerShell installation support.

Kubescape's command-line interface provides specialized commands for scanning, image patching, framework listing, offline artifact downloading, configuration management, operator interaction, and Validating Admission Policy management. The platform supports multiple output formats and includes offline capabilities for air-gapped environments. The repository maintains connections with related projects through overlapping contributors with envoyproxy/gateway, kubernetes-sigs/kubespray, and envoyproxy/envoy, indicating integration within the broader Kubernetes and cloud-native ecosystem.

kubescape
by
kubescapekubescape/kubescape

Repository Details

Fetching additional details & charts...