Ross ROSS = Recommend OSS · open-source software intelligence for agents

valqore/valqore

Safety-first guardrails for AI-driven cloud and Kubernetes operations observed · 2026-08-28

github.com/valqore/valqore · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

81/100

  • Activity 99
  • Release rhythm 98
  • Longevity 13

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0
  • age_days: 182
  • days_rel: 17
  • days_push: 9
  • n_releases_24m: 10

Full methodology

Adoption not part of the score

1831 stars · 83 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Valqore is a deterministic infrastructure governance engine that scans Kubernetes manifests, Terraform, Helm, and cloud resources against 1,428 built-in rules spanning security, cost, carbon, compliance, and AI governance, returning a 0-100 score and a PASS/BLOCK verdict. It runs locally via Docker (read-only, air-gap capable) and ships as a CLI, Kubernetes admission controller, VS Code extension, and MCP tool server for gating AI agent actions.

Use cases

  • scan kubernetes manifests for security misconfigurations before deploy
  • check terraform plans against compliance packs like SOC2 or HIPAA
  • gate AI agent infrastructure changes with human approval
  • estimate cloud cost and carbon footprint of IaC changes
  • enforce policy in CI/CD pipelines with pass/block verdicts
  • detect manual cloud drift and attribute who made it
  • audit AI workloads and agents for EU AI Act compliance

When to choose

  • you want one tool combining IaC security scanning, cost, carbon, and compliance checks instead of stitching together Checkov, Kubecost, and Kyverno
  • you need deterministic, reproducible verdicts for CI gates or auditors
  • you must gate autonomous AI agent actions on production infrastructure
  • you need air-gapped or zero-egress scanning for regulated environments

When to avoid

  • you need deep vulnerability scanning of container images or dependencies (Trivy-style CVE databases)
  • you want a managed SaaS dashboard with score trending out of the box (enterprise-only)
  • you need runtime threat detection or write-access remediation - Valqore is strictly read-only

Facets

cli-tool · maturity active

security vulnerability-scanning infrastructure-as-code mcp monitoring cli security cloud-computing infrastructure-as-code legal cli cross-platform python self-hosted policy-as-code iac-scanning finops greenops ai-governance admission-control compliance-packs agent-gate drift-detection air-gapped devops containers docker kubernetes

9 sources

Member repositories

RepositoryRoleHealth v2
valqore/valqoremain81

For agents

markdown · JSON · MCP: product_card(name="valqore/valqore")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem