Ross ROSS = Recommend OSS · open-source software intelligence for agents

openclarity/openclarity

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure observed · 2026-08-28

github.com/openclarity/openclarity · homepage · Go · Apache-2.0 (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 84
  • Release rhythm 40
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 17.0
  • age_days: 2355
  • days_rel: 574
  • days_push: 101
  • n_releases_24m: 5

Full methodology

Adoption not part of the score

1460 stars · 174 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

OpenClarity is an open-source platform for agentless detection and management of Virtual Machine SBOMs and security threats such as vulnerabilities, exploits, malware, rootkits, misconfigurations, and leaked secrets. It unifies multiple open-source security scanners into a single deployable stack with consolidated reporting and visualization.

Use cases

  • scan virtual machines for vulnerabilities without installing agents
  • generate SBOMs for VM filesystems across AWS, Azure, and GCP
  • detect leaked secrets and passwords in cloud workloads
  • find malware and rootkits on virtual machines
  • unify security scanner reporting for cloud native infrastructure
  • discover and assess VM assets across hyperscalers

When to choose

  • you need agentless security scanning of VMs across multiple cloud providers
  • you want a single platform aggregating vulnerability, malware, secret, and misconfiguration findings
  • you need SBOM generation for virtual machine filesystems
  • you prefer self-hosted, open-source cloud security tooling

When to avoid

  • you only need container image scanning without VM support
  • you require a managed SaaS security product with vendor support
  • you need runtime intrusion detection with continuous agent-based monitoring

Facets

service · maturity active

security vulnerability-scanning monitoring developer-tools security cloud-computing infrastructure-as-code cloud self-hosted go cli sbom vm-scanning agentless malware-detection leaked-secrets rootkits supply-chain-security exploits misconfiguration-detection devops containers docker kubernetes

1 source

Member repositories

RepositoryRoleHealth v2
openclarity/openclaritymain10

For agents

markdown · JSON · MCP: product_card(name="openclarity/openclarity")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem