* [cnspec v13.37.0](https://github.com/mondoohq/cnspec) – Cloud-native policy-as-code engine that scans infrastructure, containers, Kubernetes, cloud services, and code for vulnerabilities and misconfigurations. * [Open Policy Agent v1.20.0](https://github.com/open-policy-agent/opa) – General-purpose policy engine for unified, context-aware policy enforcement across various systems. * [Chainloop v1.107.0](https://github.com/chainloop-dev/chainloop) – Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports. * [ISMS Builder v1.40.0](https://github.com/coolstartnow/isms-builder) – Self-hosted web platform for managing information security compliance across ISO 27001, NIS2, GDPR, and BSI IT-Grundschutz. * [Bearer v2.1.1](https://github.com/Bearer/bearer) – Static application security testing tool that analyzes source code and data flows to find, filter, and prioritize security and privacy risks. * [FinSight Pro v0.8.0](https://github.com/Ali-Marandi/finsight-pro) – Offline Windows desktop app that combines seven financial analysis engines with ratio analysis, AI copilot chat, bankruptcy prediction, and TSETMC live data. * [restoredrill v0.1.1](https://github.com/ahmadpiran/restoredrill) – CI-native PostgreSQL backup restore verification tool that runs restores in a throwaway container, performs defined checks, and outputs auditor-ready JSON evidence. * [opa-envoy-plugin v1.20.1-envoy](https://github.com/open-policy-agent/opa-envoy-plugin) – Extends OPA to enforce fine-grained, context-aware policies for Envoy via the External Authorization gRPC API. * [Plumber v0.4.48](https://github.com/getplumber/plumber) – CI/CD compliance scanner for GitLab pipelines