devsecops
Tracked open-source repos tagged devsecops, sorted by stars.
- #31
nodejsscan is a static security code scanner for Node.js applications.
★ 2,574+2Star change over the last 7 days - #32
A FREE pragmatic DevOps learning to kickstart your DevOps career and knowledge in the Cloud Native era following the Agile MVP style! ⭐ (2026 plans for DevOps, Cloud, Platform, SRE, SWE)
★ 2,485+1Star change over the last 7 days - #33
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
★ 2,472+1Star change over the last 7 days - #34
Awesome Trainings from Cloud Native Computing Foundation Projects and Kubernetes related software
★ 2,411+1Star change over the last 7 days - #35
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
★ 2,297+0Star change over the last 7 days - #36
♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎
★ 2,163+4Star change over the last 7 days - #37
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
★ 2,062+7Star change over the last 7 days - #38
This is a step-by-step guide to implementing a DevSecOps program for any size organization
★ 2,051-1Star change over the last 7 days - #39
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
★ 1,995+1Star change over the last 7 days - #40
Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.
★ 1,995+0Star change over the last 7 days - #41
This repo includes Books and imp notes related to GCP, Azure, AWS, Docker, K8s, and DevOps. More, exam and interview prep notes.
★ 1,983+3Star change over the last 7 days - #42
Find leaked secrets everywhere.
★ 1,828+18Star change over the last 7 days - #43
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
★ 1,805+2Star change over the last 7 days - #44
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
★ 1,756+3Star change over the last 7 days - #45
Curating the best DevSecOps resources and tooling.
★ 1,720+0Star change over the last 7 days - #46★ 1,704+1Star change over the last 7 days
- #47
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
★ 1,695+4Star change over the last 7 days - #48
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
★ 1,643+11Star change over the last 7 days - #49
Checklist for container security - devsecops practices
★ 1,620+0Star change over the last 7 days - #50
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
★ 1,469+0Star change over the last 7 days - #51
Vulnerable app with examples showing how to not use secrets
★ 1,459+0Star change over the last 7 days - #52
Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.
★ 1,454+2Star change over the last 7 days - #53★ 1,412+24Star change over the last 7 days
- #54
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
★ 1,408+1Star change over the last 7 days - #55
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
★ 1,367+136Star change over the last 7 days - #56
🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍
★ 1,320+0Star change over the last 7 days - #57
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
★ 1,304-1Star change over the last 7 days - #58
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
★ 1,282+0Star change over the last 7 days - #59
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. Hundreds of rules.
★ 1,220+4Star change over the last 7 days - #60
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
★ 1,129+3Star change over the last 7 days