Refolk

Top Go Security repositories on GitHub

Offensive and defensive security tools and libraries. Filtered to projects whose primary language is Go.

Ranked by stars across 813 Go repositories tagged security. Refreshed daily.

  1. 1
    caddyserver/caddy73,458 · ⑂ 4,782

    Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

    • go
    • web-server
    • caddyfile
    • http
    • http-server
    • reverse-proxy
  2. 2
    aquasecurity/trivy36,509 · ⑂ 483

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    • security
    • security-tools
    • docker
    • containers
    • vulnerability-scanners
    • vulnerability-detection
  3. 3
    projectdiscovery/nuclei29,292 · ⑂ 3,499

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

    • cve-scanner
    • subdomain-takeover
    • nuclei-engine
    • vulnerability-detection
    • vulnerability-assessment
    • vulnerability-scanner
  4. 4
    authelia/authelia28,100 · ⑂ 1,421

    The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

    • totp
    • ldap
    • sso-authentication
    • yubikey
    • two-factor-authentication
    • docker
  5. 5
    gitleaks/gitleaks27,792 · ⑂ 2,122

    Find secrets with Gitleaks 🔑

    • security
    • security-tools
    • git
    • golang
    • go
    • secret
  6. 6
    trufflesecurity/trufflehog26,832 · ⑂ 2,471

    Find, verify, and analyze leaked credentials

    • secret
    • trufflehog
    • credentials
    • security
    • devsecops
    • dynamic-analysis
  7. 7
    cilium/cilium24,559 · ⑂ 3,841

    eBPF-based Networking, Security, and Observability

    • containers
    • bpf
    • security
    • kubernetes
    • kubernetes-networking
    • cni
  8. 8
    slimtoolkit/slim23,312 · ⑂ 833

    Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)

    • docker
    • containers
    • security
    • seccomp
    • apparmor
    • minify-images
  9. 9
    getsops/sops22,160 · ⑂ 1,041

    Simple and flexible tool for managing secrets

    • security
    • secret-distribution
    • devops
    • aws
    • pgp
    • gcp
  10. 10
    chaitin/SafeLine21,537 · ⑂ 1,412

    SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

    • firewall
    • http-flood
    • security
    • sql-injection
    • waf
    • web-application-firewall
  11. 11
    gravitational/teleport20,512 · ⑂ 2,094

    The easiest, and most secure way to access and protect all of your infrastructure.

    • ssh
    • go
    • bastion
    • teleport-binaries
    • certificate
    • golang
  12. 12
    twpayne/chezmoi20,323 · ⑂ 648

    Manage your dotfiles across multiple diverse machines, securely.

    • dotfiles
    • configuration
    • security
    • macos
    • linux
    • windows
  13. 13
    TecharoHQ/anubis20,107 · ⑂ 630

    Weighs the soul of incoming HTTP requests to stop AI crawlers

    • defense
    • security
  14. 14
    bettercap/bettercap19,441 · ⑂ 1,664

    The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

    • password-sniffer
    • mitm
    • rogue-ap
    • wifi
    • hacking
    • security
  15. 15
    ory/hydra17,233 · ⑂ 1,582

    Internet-scale OpenID Certified™ OpenID Connect and OAuth2.1 provider that integrates with your user management through headless APIs. Solve OIDC/OAuth2 user cases over night. Consume as a service on Ory Network or self-host. Trusted by OpenAI and many others for scale and security. Written in Go.

    • hydra
    • oauth2
    • openid-connect
    • docker
    • server
    • security
  16. 16
    bytebase/bytebase14,167 · ⑂ 946

    World's most advanced database DevSecOps solution for Developer, Security, DBA and Platform Engineering teams. The GitHub/GitLab for database DevSecOps.

    • mysql
    • tidb
    • postgresql
    • snowflake
    • cicd
    • sql-client
  17. 17
    shadow1ng/fscan14,010 · ⑂ 1,894

    一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

    • fscan
    • scanner
    • scanning
    • sec
    • security-tools
    • security
  18. 18
    crowdsecurity/crowdsec13,971 · ⑂ 662

    CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

    • security
    • linux
    • protection
    • detection
    • attacks-prevention
    • ids
  19. 19
    gophish/gophish13,944 · ⑂ 2,916

    Open-Source Phishing Toolkit

    • gophish
    • phishing
    • golang
    • security
  20. 20
    anchore/grype12,457 · ⑂ 813

    A vulnerability scanner for container images and filesystems

    • containers
    • security
    • vulnerability
    • docker
    • golang
    • go
  21. 21
    future-architect/vuls12,191 · ⑂ 1,236

    Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

    • vuls
    • vulnerability-scanners
    • golang
    • go
    • linux
    • freebsd
  22. 22
    gravitl/netmaker11,633 · ⑂ 643

    Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.

    • wireguard
    • vpn
    • mesh
    • zero-trust
    • devsecops
    • k8s
  23. 23
    kubescape/kubescape11,487 · ⑂ 950

    Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

    • kubernetes
    • security
    • nsa
    • mitre-attack
    • devops
    • best-practice
  24. 24
    go-acme/lego9,681 · ⑂ 1,148

    Let's Encrypt/ACME client and library written in Go

    • letsencrypt
    • acme
    • certificate
    • tls
    • security
    • acme-client
  25. 25
    majd/ipatool9,451 · ⑂ 804

    Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

    • ios
    • appstore
    • apple
    • ipa
    • itunes
    • cli

Find Go engineers shipping Security

The list above ranks the most-starred public Go repositories tagged with the Security topic, drawn from the public GitHub graph. Across 813 matching repositories, the contributors are a tight cluster of engineers with both Go chops and real Security experience.

That overlap is rare. Most Go engineers haven’t shipped Security, and most Security maintainers don’t write Go. The people on this list’s contributor graph are the ones who do both.

Refolk turns this list into a search. Ask for Go Security maintainers hiring” or Go engineers shipping Security in 2025” and Refolk returns a ranked shortlist with the commits, profiles, and projects behind each name.

How this list is built

Refolk searched GitHub for public Go repositories tagged with the Security topic, ranked them by stargazer count, and kept those with at least 25 stars. The list refreshes once a day.

Last refreshed: Sun, 21 Jun 2026 11:20:55 GMT

Need a more specific search?

Refolk runs natural-language searches across GitHub, LinkedIn, and the open web. Try one of these:

Related lists

See all repository lists.

Or zoom out