Ross ROSS = Recommend OSS · open-source software intelligence for agents

ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP) observed · 2026-08-28

github.com/deepfence/ThreatMapper · homepage · TypeScript · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 85
  • Release rhythm 74
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 17.5
  • age_days: 2400
  • days_rel: 179
  • days_push: 93
  • n_releases_24m: 13

Full methodology

Adoption not part of the score

5318 stars · 631 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Deepfence ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) that hunts threats in production cloud, Kubernetes, serverless, and on-prem environments, ranking them by risk-of-exploit. It bundles SecretScanner for exposed secrets and YaraHunter for malware indicators, generating runtime SBOMs and compliance checks.

Use cases

  • scan kubernetes clusters for vulnerabilities and misconfigurations
  • find exposed secrets and api keys in container images
  • detect malware in running docker containers
  • generate runtime SBOMs from production workloads
  • check cloud infrastructure against CIS and PCI-DSS compliance benchmarks
  • prioritize vulnerabilities by risk of exploit
  • visualize attack paths in cloud native applications

When to choose

  • you need runtime security observability for containers, Kubernetes, or serverless workloads
  • you want a self-hosted, fully open-source CNAPP with no feature limits
  • you need combined vulnerability, secret, malware, and compliance scanning in one console
  • you want to rank threats by exploitability rather than raw CVSS scores

When to avoid

  • you only need lightweight CI-time image scanning without a management console
  • you require a managed SaaS security product with vendor support
  • your workloads are not containerized or cloud-based
  • you need deep host-based endpoint detection beyond container and cloud scanning

Facets

application · maturity active

security vulnerability-scanning monitoring secrets-management container-runtime container-orchestration security cloud-computing cloud self-hosted cnapp cwpp cspm devsecops threat-detection sbom attack-path-analysis runtime-security yara malware-scanning compliance containers devops kubernetes docker linux

8 sources

Member repositories

RepositoryRoleHealth v2
deepfence/ThreatMappermain84
deepfence/SecretScannerplugin74
deepfence/YaraHunterplugin74

For agents

markdown · JSON · MCP: product_card(name="deepfence/ThreatMapper")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem