# someengineering/fixinventory

Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.

Repository: https://github.com/someengineering/fixinventory
Canonical: https://ross.abutalabs.com/products/fixinventory
Homepage: https://fixinventory.org
Language: Python
License: Apache-2.0
License Family: permissive
Topics: aws, gcp, infrastructure-as-code, digitalocean, security, security-automation, cnapp, cspm, cybersecurity, policy-as-code, security-audit
Last push: 2026-03-28T19:14:05+00:00

## Health v2 (maintenance only)
Score: 56/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 74, release rhythm 8, longevity 100
- inputs: {"age_days": 2332, "days_push": 158, "days_rel": 636, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2074, forks 137 (observed 2026-08-28T04:06:10.700020+00:00)

## What it is
Fix Inventory is an open-source cloud asset inventory and security tool that collects metadata from cloud providers (AWS, GCP, Azure, DigitalOcean, Hetzner, Kubernetes, GitHub), normalizes it into a graph data model, and scans it for compliance and security risks. It includes a powerful CLI shell for searching and exploring resources plus automations for tagging and cleanup.

## Use cases
- find security misconfigurations in my AWS accounts
- build a searchable inventory of all cloud resources across providers
- run CIS benchmark compliance checks on cloud infrastructure
- clean up untagged or unused cloud resources automatically
- open source alternative to Wiz or Orca Security
- explore cloud resource dependencies as a graph
- audit Kubernetes clusters for security risks

## When to choose
- you need agentless multi-cloud asset inventory and CSPM in one tool
- you want a CLI/graph-based way to query cloud resources across AWS, GCP, Azure, and K8s
- you prefer self-hosted open source over proprietary CNAPP vendors
- you want to automate tagging, cleanup, and policy checks with custom rules

## When to avoid
- you need a managed SaaS dashboard with turnkey setup (consider the vendor's Fix Security instead)
- you only need vulnerability scanning of workloads rather than configuration/compliance analysis
- you require real-time runtime threat detection rather than periodic inventory scans

## Facets
- artifact type: service
- maturity: active
- function: security, monitoring, search-engine, cli, infrastructure-as-code
- domain: security, cloud-computing, infrastructure-as-code, self-hosted
- platform: self-hosted, cloud, cli, python
- tags: cspm, cnapp, cloud-security, asset-inventory, policy-as-code, aws, gcp, azure, kubernetes, compliance, agentless, devops, docker

## Member repositories
- someengineering/fixinventory (main) score 56

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:10.700020+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:56:23.217738+00:00, confidence not recorded.
  - readme: https://github.com/someengineering/fixinventory (fetched 2026-08-28T04:06:10.700020+00:00, sha 24b18471632e)
  - homepage: https://fixinventory.org (fetched 2026-08-29T10:36:39.670528+00:00, sha f08e81920c38)
  - site_page: https://fixinventory.org/getting-started (fetched 2026-08-29T10:36:39.682115+00:00, sha 107324cfe0bc)
  - site_page: https://fixinventory.org/releases/4.2.0 (fetched 2026-08-29T10:36:39.679722+00:00, sha 8299eb38a008)
- Data as of 2026-08-30T08:39:29.467469+00:00.
