mondoohq/cnspec: An open source, cloud-native security to protect everything from build to runtime

3 phút đọc

mondoohq/cnspec: An open source, cloud-native security to protect everything from build to runtime – Repository mondoohq/cnspec. Mô tả: An open source, cloud-native security to protect everything from build to runtime. 442 stars, 40 forks, ngôn ngữ chính Go, cập nhật 2026-08-22.

1. Repository làm gì?

Open source, cloud-native security and policy project

cnspec assesses your entire infrastructure's security and compliance. It finds vulnerabilities and misconfigurations across public and private cloud environments, Kubernetes clusters, containers, container registries, servers, endpoints, SaaS products, infrastructure as code, APIs, and more.

A powerful policy as code engine, cnspec is built upon Mondoo's security data fabric. It comes configured with default security policies that run right out of the box. It's both fast and simple to use!

Install cnspec with our installation script:

If you prefer manual installation, you can find the cnspec packages in our releases.

Use the cnspec scan subcommand to check local and remote targets for misconfigurations and vulnerabilities.

2. Dữ liệu và cấu trúc đáng chú ý

This command evaluates the security of your local machine:

You can also specify remote targets to scan. For example:

📚 To learn more, read the cnspec docs.

cnspec policies are built on the concept of policy as code. cnspec comes with default security policies configured for all supported targets. The default policies are available in the content directory of this repository.

cnspec scans for vulnerabilities in a wide range of platforms. Vulnerability scanning is not restricted to container images; it works for build and runtime as well.

NOTE: Vulnerability scanning requires the client to be logged into Mondoo Platform.

cnspec also provides an interactive shell to explore assertions. It helps you understand the assertions that security policies use, as well as write your own policies. It's also a great way to interact with both local and remote targets on the fly.

3. Khả năng ứng dụng và giới hạn

The shell provides a help command for information on the resources that power cnspec. Running help without any arguments lists all of the available resources and their fields. You can also run help to get more detail on a specific resource. For example:

The shell uses auto-complete, which makes it easy to explore.

Once inside the shell, you can enter MQL assertions like this:

To clear the terminal, type clear.

To exit, either hit CTRL + D or type exit.

Prioritize risks that matter with Mondoo Platform

The Mondoo unified security platform finds and prioritizes vulnerabilities and misconfigurations that pose the highest risk to your business. Mondoo's security data fabric analyzes the threat and exposure of every finding within the unique context of your infrastructure. Instead of a flood of irrelevant security alerts, Mondoo shows you how you can make an immediate and significant impact on your security posture.

To learn about Mondoo Platform, read the Mondoo Platform docs or visit mondoo.com.

Register cnspec with Mondoo Platform

Số liệu repository có thể thay đổi; nên mở liên kết nguồn để kiểm tra README, giấy phép và trạng thái phát hành.

Nguồn tham khảo: Xem bài gốc

📆
Âm Lịch: 17/8
Giáp Thìn

📆 Lịch Âm Dương NsN

×
Hôm Nay - Chủ Nhật
Âm Lịch: 17 Tháng 8
Năm Bính Ngọ
📌 Ngày Can Chi: Giáp Thìn
✨ Giờ Hoàng Đạo: Dần (3-5), Thìn (7-9), Tỵ (9-11), Thân (15-17), Dậu (17-19), Hợi (21-23)
Vĩnh Phúc (Liên Bảo - Vĩnh Yên)
27°C
Nắng Đẹp
💧 83% | 💨 15 km/h
Hôm nay 33°
29/09 34°
30/09 33°
01/10 31°
02/10 31°