oci-seccomp-bpf-hook by containers

OCI hook to trace syscalls and generate a seccomp profile

updated at Nov. 12, 2024, 8:02 a.m.

Go

15 +0

303 +0

36 +0

GitHub
rkt by rkt

[Project ended] rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards.

updated at Nov. 12, 2024, 3:39 p.m.

Go

420 +0

8,822 -1

883 +0

GitHub
Whaler by P3GLEG

Program to reverse Docker images into Dockerfiles

updated at Nov. 12, 2024, 7:31 p.m.

Go

24 +0

1,067 +2

95 +0

GitHub
cnab-spec by cnabio

Cloud Native Application Bundle Specification

updated at Nov. 12, 2024, 8:03 p.m.

Shell

51 +0

957 +1

99 +0

GitHub
container-diff by GoogleContainerTools

container-diff: Diff your Docker containers

updated at Nov. 13, 2024, 4:18 p.m.

Go

65 +0

3,759 +1

234 +0

GitHub
singularity by apptainer

Singularity has been renamed to Apptainer as part of us moving the project to the Linux Foundation. This repo has been persisted as a snapshot right before the changes.

updated at Nov. 14, 2024, 7:47 p.m.

Go

88 +0

2,532 +2

424 +0

GitHub
swarmpit by swarmpit

Lightweight mobile-friendly Docker Swarm management UI

updated at Nov. 14, 2024, 9:31 p.m.

Clojure

68 +0

3,114 +8

285 +0

GitHub
img by genuinetools

Standalone, daemon-less, unprivileged Dockerfile and OCI compatible container image builder.

updated at Nov. 15, 2024, 5:59 a.m.

Go

51 +0

3,908 +1

231 +0

GitHub
bubblewrap by containers

Low-level unprivileged sandboxing tool used by Flatpak and similar projects

updated at Nov. 15, 2024, 5:23 p.m.

C

55 +0

3,966 +12

237 +0

GitHub
porto by yandex

Yet another Linux container management system

updated at Nov. 15, 2024, 9:53 p.m.

C++

44 +0

397 -1

52 +0

GitHub
photon by vmware

Minimal Linux container host

updated at Nov. 15, 2024, 11:53 p.m.

Python

188 +0

3,049 +2

697 +1

GitHub
nsjail by google

A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.

updated at Nov. 16, 2024, 5:34 a.m.

C++

88 -1

2,979 +9

274 +0

GitHub
sysbox by nestybox

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

updated at Nov. 16, 2024, 7 a.m.

Shell

39 +0

2,812 +9

155 +0

GitHub
udocker by indigo-dc

A basic user tool to execute simple docker containers in batch or interactive systems without root privileges.

updated at Nov. 16, 2024, 4:10 p.m.

Python

34 +0

1,371 +8

133 +0

GitHub
bocker by p8952

Docker implemented in around 100 lines of bash

updated at Nov. 16, 2024, 4:15 p.m.

Shell

271 +0

11,295 +5

718 +1

GitHub
incus by lxc

Powerful system container and virtual machine manager

updated at Nov. 16, 2024, 6:41 p.m.

Go

46 +0

2,746 +22

225 +1

GitHub
docker-bench-security by docker

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

updated at Nov. 16, 2024, 7:52 p.m.

Shell

234 +1

9,148 +21

1,017 +1

GitHub
go-containerregistry by google

Go library and CLIs for working with container registries

updated at Nov. 16, 2024, 8:15 p.m.

Go

31 -1

3,143 +9

543 +1

GitHub
goss by goss-org

Quick and Easy server testing/validation

updated at Nov. 16, 2024, 10:12 p.m.

Go

82 +0

5,614 +10

472 -1

GitHub
moby by moby

The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems

updated at Nov. 16, 2024, 11:27 p.m.

Go

2,884 -5

68,759 +42

18,665 -1

GitHub