Bandit
Static analysis tool that scans Python source for common security issues such as hardcoded credentials, unsafe subprocess calls and weak cryptography.
Open-source authentication server offering passwordless login, social sign-in, MFA and user management through OIDC-compatible APIs and a hosted admin portal. Built and maintained by WIEWAVE for Azure Marketplace and AWS Marketplace, on Ubuntu and Debian.
| Built & maintained by | WIEWAVE |
|---|---|
| Category | Security |
| Operating systems | Ubuntu, Debian |
| Marketplaces | Azure Marketplace and AWS Marketplace |
| Offer types | Public listing, with private offers on request |
| Marketplace | Status |
|---|---|
| Azure Marketplace | Published |
| AWS Marketplace | Published |
| Google Cloud Marketplace | Available on request |
Need it on another marketplace, or as a private offer for your organisation? cloud@wiewave.com
Each image follows its distribution's own provisioning model, package manager and security tooling — not one build relabelled several times.
LTS and interim releases, Minimal and Pro variants, built to Canonical's cloud-image conventions.
Stable and oldstable, with backports where a workload needs a newer runtime than the release ships.
The same four steps behind every offer we've published, including the hardening and CIS Benchmark checks every build goes through.
The distribution, licensing model and target marketplaces are agreed before anything is built.
Packer templates, Ansible provisioning and a pinned package set — then hardened, scanned and checked against the CIS Benchmark for its distribution.
Taken through each cloud's own certification pipeline before it goes live on the marketplace.
Rebuilt on the upstream security cadence and re-published, with old versions retired without breaking deployments.
If yours isn't here, ask our marketplace team directly.
Secrets management, identity, VPN gateways and CIS-benchmarked hardened base images.
Static analysis tool that scans Python source for common security issues such as hardcoded credentials, unsafe subprocess calls and weak cryptography.
Low-code honeypot framework written in Go that emulates SSH, HTTP and TCP services, optionally using an LLM to fake convincing shell responses.
HashiCorp's identity-based access proxy brokering just-in-time sessions to SSH, RDP and database targets without distributing network credentials to end users.
Web application firewall and reverse proxy built on NGINX, applying ModSecurity rules, bot detection, rate limiting and automatic Let's Encrypt certificates.
Helper controller from the cert-manager project that injects CA certificate bundles into Kubernetes webhook configurations, API services and custom resource definitions.
Incident response and security orchestration platform providing alert ticketing, automation playbooks and artifact enrichment for SOC analysts working through investigations.
Tell us the distribution, the marketplace and the commercial model — we'll build, certify and publish it as a public listing or a private offer.