# aquasecurity/starboard

Superseded by https://github.com/aquasecurity/trivy-operator

Repository: https://github.com/aquasecurity/starboard
Canonical: https://ross.abutalabs.com/products/starboard
Homepage: https://aquasecurity.github.io/starboard/
Language: Go
License: Apache-2.0
License Family: permissive
Topics: starboard, kubernetes, security, cloud-native, custom-resource-definition
Last push: 2026-06-10T12:05:58+00:00

## Health v2 (maintenance only)
Score: 85/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 86, release rhythm 74, longevity 100
- inputs: {"age_days": 2360, "days_push": 84, "days_rel": 92, "gap_med": 48, "n_releases_24m": 12}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1380, forks 200 (observed 2026-08-28T04:04:33.890140+00:00)

## What it is
Starboard is a Kubernetes-native security toolkit that integrates heterogeneous security scanners and exposes their results as Kubernetes Custom Resource Definitions accessible via the Kubernetes API. It has been discontinued and merged into Trivy and the Trivy-Operator.

## Use cases
- scan kubernetes workloads for vulnerabilities
- audit kubernetes resource configurations with OPA policies
- run CIS benchmark compliance checks on a cluster
- generate NSA/CISA kubernetes hardening compliance reports
- view security reports for pods in Lens or Octant
- store penetration test results as kubernetes CRDs

## When to choose
- you are already invested in the Starboard CLI or operator and need its exact CRD schema
- you need a Go module to integrate security scanner outputs into Kubernetes CRDs

## When to avoid
- starting a new project - use trivy-operator and trivy kubernetes instead
- you need ongoing support or new features
- you want actively maintained vulnerability scanning for Kubernetes

## Facets
- artifact type: application
- maturity: abandoned
- function: security, vulnerability-scanning, monitoring, container-orchestration
- domain: security, cloud-computing
- platform: go, self-hosted
- tags: kubernetes-security, crd, vulnerability-scanning, cis-benchmarks, superseded, trivy-operator, octant-plugin, lens-extension, containers, devops, kubernetes, docker

## Member repositories
- aquasecurity/starboard (main) score 85

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:33.890140+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:40:13.959081+00:00, confidence not recorded.
  - readme: https://github.com/aquasecurity/starboard (fetched 2026-08-28T04:04:33.890140+00:00, sha 21eb1c42d35c)
  - homepage: https://aquasecurity.github.io/starboard/ (fetched 2026-08-29T11:56:08.349951+00:00, sha 37b0d4ae981c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
