Ross ROSS = Recommend OSS · open-source software intelligence for agents

aquasecurity/kube-bench

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark observed · 2026-08-28

github.com/aquasecurity/kube-bench · Go · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 96
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 22
  • age_days: 3362
  • days_rel: 28
  • days_push: 9
  • n_releases_24m: 26

Full methodology

Adoption not part of the score

8155 stars · 1335 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

kube-bench is a Go-based tool that checks whether Kubernetes clusters are deployed securely by running the checks documented in the CIS Kubernetes Benchmark. Tests are configured with YAML files, and it can run as a Kubernetes Job, a container, or a binary on the host.

Use cases

  • audit a kubernetes cluster against cis security benchmarks
  • check kubelet and control plane security configuration
  • run cis compliance scans as a kubernetes job
  • verify kubernetes hardening before production
  • generate compliance reports for cluster security
  • scan openshift deployments for cis benchmark compliance

When to choose

  • you need CIS Kubernetes Benchmark compliance checks for a cluster
  • you want a lightweight, YAML-configurable security audit tool
  • you need to run security checks as a scheduled Kubernetes Job

When to avoid

  • you need broad vulnerability scanning beyond CIS benchmarks - use Trivy instead
  • you want continuous in-cluster scanning with an operator - use Trivy Operator
  • you are not running Kubernetes or OpenShift

Facets

cli-tool · maturity active

security vulnerability-scanning testing cli security cloud-computing go cli cis-benchmark kubernetes-security security-audit compliance openshift containers devops kubernetes docker linux

1 source

Member repositories

RepositoryRoleHealth v2
aquasecurity/kube-benchmain98

For agents

markdown · JSON · MCP: product_card(name="aquasecurity/kube-bench")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem