7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Kubescape

Open source

Open-source Kubernetes security platform covering misconfiguration scanning, image vulnerabilities, compliance checks and runtime monitoring.

kubescape.io
Kubescape homepage screenshot
GitHub stars
12k
Last commit
today
Repository age
5 years
Version
v4.0.15
Licence
Apache-2.0
Self-hosted
Yes

About Kubescape

Kubescape is an open-source Kubernetes security platform that covers the lifecycle from development to runtime. It was created by ARMO and is a Cloud Native Computing Foundation incubating project. It works in an IDE, in CI/CD pipelines and against running clusters, with the aim of saving administrators time on risk analysis and compliance work.

Misconfiguration scanning checks clusters, YAML files and Helm charts against NSA-CISA guidance, MITRE ATT&CK and CIS Benchmarks. Image vulnerability scanning detects CVEs using Grype, image patching uses Copacetic, and auto-remediation can fix manifest issues. Admission control uses Validating Admission Policies, runtime monitoring is eBPF-based through Inspektor Gadget, and an MCP server connects AI assistants.

Kubescape is written in Go and released under the Apache-2.0 license. It installs through options such as Homebrew and Krew, and an in-cluster operator is available for continuous scanning. Results include an overview of control plane status, access control risks, workload misconfigurations, network policy gaps and compliance scores.

Key features

  • Misconfiguration scanning against NSA-CISA, MITRE, CIS
  • Image vulnerability scanning with Grype
  • Automatic image patching with Copacetic
  • Auto-remediation for Kubernetes manifests
  • eBPF-based runtime security monitoring
  • In-cluster operator and MCP server

Good fit for

  • →Scanning Helm charts in CI pipelines
  • →Tracking Kubernetes compliance scores
Built with
Go
Kubernetes
Tags
kubernetes
security
compliance
devsecops
ebpf
cncf
vulnerability-scanning
go

Kubescape: questions and answers

What is Kubescape used for?
Kubescape is an open-source Kubernetes security platform covering misconfiguration scanning, image vulnerabilities, compliance checks and runtime monitoring. It is a good fit for scanning Helm charts in CI pipelines and tracking Kubernetes compliance scores.
Is Kubescape open source?
Yes. Kubescape is open source under the Apache-2.0 licence. Its source code is on GitHub at kubescape/kubescape and is written mainly in Go.
Is Kubescape free?
Yes. Kubescape is open source, so the software itself is free to use.
What is Kubescape an alternative to?
Kubescape is an open-source alternative to Wiz, Palo Alto Networks, Aikido Security and Orca Security. Other open-source alternatives to Wiz include Trivy, Falco and Grype.
Is Kubescape actively maintained?
Yes. The most recent commit to Kubescape was on 2 October 2026, and the latest release is v4.0.15, published on 29 September 2026. The project has 12k stars on GitHub.

Open-source alternatives to Kubescape

See all

SaaS alternatives to Kubescape

See all