# openclarity/openclarity

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Repository: https://github.com/openclarity/openclarity
Canonical: https://ross.abutalabs.com/products/openclarity
Homepage: https://openclarity.io
Language: Go
License: Apache-2.0
License Family: permissive
Topics: cloud, exploits, kubernetes, leaked-secrets, malware, rootkits, sbom, scanner, security, supply-chain, virtual-machine, vulnerabilities
Archived: true
Last push: 2026-05-25T02:27:26+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 84, release rhythm 40, longevity 100
- inputs: {"age_days": 2355, "days_push": 101, "days_rel": 574, "gap_med": 17.0, "n_releases_24m": 5}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1460, forks 174 (observed 2026-08-28T04:04:47.304461+00:00)

## What it is
OpenClarity is an open-source platform for agentless detection and management of Virtual Machine SBOMs and security threats such as vulnerabilities, exploits, malware, rootkits, misconfigurations, and leaked secrets. It unifies multiple open-source security scanners into a single deployable stack with consolidated reporting and visualization.

## Use cases
- scan virtual machines for vulnerabilities without installing agents
- generate SBOMs for VM filesystems across AWS, Azure, and GCP
- detect leaked secrets and passwords in cloud workloads
- find malware and rootkits on virtual machines
- unify security scanner reporting for cloud native infrastructure
- discover and assess VM assets across hyperscalers

## When to choose
- you need agentless security scanning of VMs across multiple cloud providers
- you want a single platform aggregating vulnerability, malware, secret, and misconfiguration findings
- you need SBOM generation for virtual machine filesystems
- you prefer self-hosted, open-source cloud security tooling

## When to avoid
- you only need container image scanning without VM support
- you require a managed SaaS security product with vendor support
- you need runtime intrusion detection with continuous agent-based monitoring

## Facets
- artifact type: service
- maturity: active
- function: security, vulnerability-scanning, monitoring, developer-tools
- domain: security, cloud-computing, infrastructure-as-code
- platform: cloud, self-hosted, go, cli
- tags: sbom, vm-scanning, agentless, malware-detection, leaked-secrets, rootkits, supply-chain-security, exploits, misconfiguration-detection, devops, containers, docker, kubernetes

## Member repositories
- openclarity/openclarity (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:47.304461+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:35:25.133043+00:00, confidence not recorded.
  - readme: https://github.com/openclarity/openclarity (fetched 2026-08-28T04:04:47.304461+00:00, sha 4c71f015e78b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
