Refolk

Top Go Security repositories on GitHub

Offensive and defensive security tools and libraries. Filtered to projects whose primary language is Go.

Ranked by stars across 796 Go repositories tagged security. Refreshed daily.

  1. 1
    caddyserver/caddy72,136 · ⑂ 4,714

    Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

    • go
    • web-server
    • caddyfile
    • http
    • http-server
    • reverse-proxy
  2. 2
    aquasecurity/trivy34,879 · ⑂ 348

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    • security
    • security-tools
    • docker
    • containers
    • vulnerability-scanners
    • vulnerability-detection
  3. 3
    projectdiscovery/nuclei28,250 · ⑂ 3,387

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

    • cve-scanner
    • subdomain-takeover
    • nuclei-engine
    • vulnerability-detection
    • vulnerability-assessment
    • vulnerability-scanner
  4. 4
    authelia/authelia27,716 · ⑂ 1,396

    The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

    • totp
    • ldap
    • sso-authentication
    • yubikey
    • two-factor-authentication
    • docker
  5. 5
    gitleaks/gitleaks26,615 · ⑂ 2,021

    Find secrets with Gitleaks 🔑

    • security
    • security-tools
    • git
    • golang
    • go
    • secret
  6. 6
    trufflesecurity/trufflehog26,068 · ⑂ 2,371

    Find, verify, and analyze leaked credentials

    • secret
    • trufflehog
    • credentials
    • security
    • devsecops
    • dynamic-analysis
  7. 7
    cilium/cilium24,291 · ⑂ 3,751

    eBPF-based Networking, Security, and Observability

    • containers
    • bpf
    • security
    • kubernetes
    • kubernetes-networking
    • cni
  8. 8
    slimtoolkit/slim23,199 · ⑂ 827

    Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)

    • docker
    • containers
    • security
    • seccomp
    • apparmor
    • minify-images
  9. 9
    getsops/sops21,702 · ⑂ 1,022

    Simple and flexible tool for managing secrets

    • security
    • secret-distribution
    • devops
    • aws
    • pgp
    • gcp
  10. 10
    chaitin/SafeLine21,229 · ⑂ 1,382

    SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

    • firewall
    • http-flood
    • security
    • sql-injection
    • waf
    • web-application-firewall
  11. 11
    gravitational/teleport20,250 · ⑂ 2,056

    The easiest, and most secure way to access and protect all of your infrastructure.

    • ssh
    • go
    • bastion
    • teleport-binaries
    • certificate
    • golang
  12. 12
    twpayne/chezmoi19,581 · ⑂ 640

    Manage your dotfiles across multiple diverse machines, securely.

    • dotfiles
    • configuration
    • security
    • macos
    • linux
    • windows
  13. 13
    bettercap/bettercap19,169 · ⑂ 1,639

    The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

    • password-sniffer
    • mitm
    • rogue-ap
    • wifi
    • hacking
    • security
  14. 14
    TecharoHQ/anubis19,054 · ⑂ 594

    Weighs the soul of incoming HTTP requests to stop AI crawlers

    • defense
    • security
  15. 15
    ory/hydra17,117 · ⑂ 1,567

    Internet-scale OpenID Certified™ OpenID Connect and OAuth2.1 provider that integrates with your user management through headless APIs. Solve OIDC/OAuth2 user cases over night. Consume as a service on Ory Network or self-host. Trusted by OpenAI and many others for scale and security. Written in Go.

    • hydra
    • oauth2
    • openid-connect
    • docker
    • server
    • security
  16. 16
    bytebase/bytebase13,958 · ⑂ 935

    World's most advanced database DevSecOps solution for Developer, Security, DBA and Platform Engineering teams. The GitHub/GitLab for database DevSecOps.

    • mysql
    • tidb
    • postgresql
    • snowflake
    • cicd
    • sql-client
  17. 17
    gophish/gophish13,806 · ⑂ 2,887

    Open-Source Phishing Toolkit

    • gophish
    • phishing
    • golang
    • security
  18. 18
    shadow1ng/fscan13,705 · ⑂ 1,884

    一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

    • fscan
    • scanner
    • scanning
    • sec
    • security-tools
    • security
  19. 19
    crowdsecurity/crowdsec13,261 · ⑂ 614

    CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

    • security
    • linux
    • protection
    • detection
    • attacks-prevention
    • ids
  20. 20
    anchore/grype12,157 · ⑂ 793

    A vulnerability scanner for container images and filesystems

    • containers
    • security
    • vulnerability
    • docker
    • golang
    • go
  21. 21
    future-architect/vuls12,131 · ⑂ 1,233

    Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

    • vuls
    • vulnerability-scanners
    • golang
    • go
    • linux
    • freebsd
  22. 22
    gravitl/netmaker11,566 · ⑂ 637

    Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.

    • wireguard
    • vpn
    • mesh
    • zero-trust
    • devsecops
    • k8s
  23. 23
    kubescape/kubescape11,366 · ⑂ 924

    Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

    • kubernetes
    • security
    • nsa
    • mitre-attack
    • devops
    • best-practice
  24. 24
    go-acme/lego9,526 · ⑂ 1,125

    Let's Encrypt/ACME client and library written in Go

    • letsencrypt
    • acme
    • certificate
    • tls
    • security
    • acme-client
  25. 25
    majd/ipatool9,176 · ⑂ 753

    Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

    • ios
    • appstore
    • apple
    • ipa
    • itunes
    • cli

Find Go engineers shipping Security

The list above ranks the most-starred public Go repositories tagged with the Security topic, drawn from the public GitHub graph. Across 796 matching repositories, the contributors are a tight cluster of engineers with both Go chops and real Security experience.

That overlap is rare. Most Go engineers haven’t shipped Security, and most Security maintainers don’t write Go. The people on this list’s contributor graph are the ones who do both.

Refolk turns this list into a search. Ask for Go Security maintainers hiring” or Go engineers shipping Security in 2025” and Refolk returns a ranked shortlist with the commits, profiles, and projects behind each name.

How this list is built

Refolk searched GitHub for public Go repositories tagged with the Security topic, ranked them by stargazer count, and kept those with at least 25 stars. The list refreshes once a day.

Last refreshed: Thu, 07 May 2026 06:52:20 GMT

Need a more specific search?

Refolk runs natural-language searches across GitHub, LinkedIn, and the open web. Try one of these:

Related lists

See all repository lists.

Or zoom out