kubescape/kubescape
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources. observed · 2026-08-28
Health v2 · maintenance only
98/100
- Activity 99
- Release rhythm 97
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 11
- age_days: 1847
- days_rel: 21
- days_push: 7
- n_releases_24m: 44
Adoption not part of the score
11692 stars · 1016 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Kubescape is an open-source Kubernetes security platform (a CNCF incubating project) offering misconfiguration scanning, vulnerability assessment, compliance checks against frameworks like NSA-CISA, CIS, and MITRE ATT&CK, and runtime threat detection. It runs as a CLI, in CI/CD pipelines, and as an in-cluster operator for continuous monitoring.
Use cases
- scan kubernetes cluster for misconfigurations
- check cluster compliance against NSA and CIS benchmarks
- find vulnerabilities in kubernetes workloads
- integrate kubernetes security scanning into CI/CD pipeline
- validate network policies and seccomp profiles
- detect runtime threats in kubernetes clusters
- audit helm charts before deployment
When to choose
- you need a single open-source tool covering kubernetes configuration, vulnerability, and compliance scanning
- you want security checks in IDEs, CI/CD pipelines, and live clusters
- you need to validate clusters against industry frameworks like NSA-CISA, MITRE ATT&CK, or SOC 2
- you want runtime threat detection alongside static posture management
When to avoid
- you need security scanning for non-Kubernetes environments
- you require a fully managed commercial platform with a single pane of glass (though ARMO offers one built on Kubescape)
- you only need container image scanning without cluster context
Facets
cli-tool · maturity active
security vulnerability-scanning monitoring ci-cd container-orchestration security cloud-computing developer-tools windows cli go kubernetes-security compliance misconfiguration-scanning cnsa mitre-attack cncf runtime-security helm devops containers linux macos kubernetes docker
10 sources
- readme: https://github.com/kubescape/kubescape · fetched 2026-08-28 · 4f88eca173f2
- homepage: https://kubescape.io · fetched 2026-08-29 · 60d8f44d027f
- site_page: https://kubescape.io/docs · fetched 2026-08-29 · 9bbda7ec9844
- site_page: https://kubescape.io/project/about · fetched 2026-08-29 · 47e2405970b2
- site_page: https://kubescape.io/docs/getting-started · fetched 2026-08-29 · 7dbd7f8c7a2b
- site_page: https://kubescape.io/docs/install-cli · fetched 2026-08-29 · 151bc3b226e5
- site_page: https://kubescape.io/docs/install-operator · fetched 2026-08-29 · 1657d5423f34
- site_page: https://kubescape.io/docs/scanning · fetched 2026-08-29 · 49f9572ceeb4
- site_page: https://kubescape.io/docs/accepting-risk · fetched 2026-08-29 · bb8990dcc226
- site_page: https://kubescape.io/docs/providers · fetched 2026-08-29 · 0f7a6b838346
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| kubescape/kubescape | main | 98 |
For agents
markdown · JSON · MCP: product_card(name="kubescape/kubescape")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem