Skip to main content
buildradar
Sign in
Topic · devsecops

devsecops

Tracked open-source repos tagged devsecops, sorted by stars.

94 repos
  • nodejsscan@ajinabraham

    nodejsscan is a static security code scanner for Node.js applications.

    2,574+2Star change over the last 7 days
  • dynamic-devops-roadmap@DevOpsHiveHQ

    A FREE pragmatic DevOps learning to kickstart your DevOps career and knowledge in the Cloud Native era following the Agile MVP style! ⭐ (2026 plans for DevOps, Cloud, Platform, SRE, SWE)

    2,485+1Star change over the last 7 days
  • archerysec@archerysec

    ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

    2,472+1Star change over the last 7 days
  • Awesome Trainings from Cloud Native Computing Foundation Projects and Kubernetes related software

    2,411+1Star change over the last 7 days
  • cicd-goat@cider-security-research

    A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

    2,297+0Star change over the last 7 days
  • DevSecOps@hahwul

    ♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎

    2,163+4Star change over the last 7 days
  • PentestingEverything@m14r41

    Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...

    2,062+7Star change over the last 7 days
  • This is a step-by-step guide to implementing a DevSecOps program for any size organization

    2,051-1Star change over the last 7 days
  • ggshield@GitGuardian

    Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.

    1,995+1Star change over the last 7 days
  • safety@pyupio

    Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.

    1,995+0Star change over the last 7 days
  • This repo includes Books and imp notes related to GCP, Azure, AWS, Docker, K8s, and DevOps. More, exam and interview prep notes.

    1,983+3Star change over the last 7 days
  • betterleaks@betterleaks

    Find leaked secrets everywhere.

    1,828+18Star change over the last 7 days
  • awesome-threat-modelling@hysnsec

    A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.

    1,805+2Star change over the last 7 days
  • cve-bin-tool@ossf

    The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

    1,756+3Star change over the last 7 days
  • awesome-devsecops@jakob-pennington

    Curating the best DevSecOps resources and tooling.

    1,720+0Star change over the last 7 days
  • copacetic@project-copacetic

    🧵 CLI tool for directly patching container images!

    1,704+1Star change over the last 7 days
  • openappsec@openappsec

    open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.

    1,695+4Star change over the last 7 days
  • pentest-ai@0xSteph

    Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

    1,643+11Star change over the last 7 days
  • Checklist for container security - devsecops practices

    1,620+0Star change over the last 7 days
  • lunasec@lunasec-io

    LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

    1,469+0Star change over the last 7 days
  • wrongsecrets@OWASP

    Vulnerable app with examples showing how to not use secrets

    1,459+0Star change over the last 7 days
  • git-hound@tillson

    Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

    1,454+2Star change over the last 7 days
  • noir@owasp-noir

    Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

    1,412+24Star change over the last 7 days
  • trivy-action@aquasecurity

    Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

    1,408+1Star change over the last 7 days
  • cve-mcp-server@mukul975

    Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

    1,367+136Star change over the last 7 days
  • YaraHunter@deepfence

    🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍

    1,320+0Star change over the last 7 days
  • terragoat@bridgecrewio

    TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    1,304-1Star change over the last 7 days
  • dep-scan@owasp-dep-scan

    OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

    1,282+0Star change over the last 7 days
  • kingfisher@mongodb

    Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. Hundreds of rules.

    1,220+4Star change over the last 7 days
  • OpenSCA-cli@XmirrorSecurity

    OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

    1,129+3Star change over the last 7 days
← Back to topics