Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Devsecops

Devsecops

148 projects

Showing 36 of 148 projects

SafeDep/vet
SafeDep/vetGo

A CLI tool for real-time malicious package detection and software supply chain security across multiple ecosystems.

#pypi#rubygems#supply-chain-security
Stars1.1k
Forks104
Last commit4 days ago
AWS Incident Response Runbook Samples
AWS Incident Response Runbook Samples

AWS incident response runbook templates for DoS/DDoS attacks, credential leakage, and S3 bucket access incidents.

#aws-security#dos-attack#credential-management
Stars1.1k
Forks234
Last commit7 days ago
DevSkim
DevSkimC#

A security linting framework with IDE plugins and CLI tools that detects vulnerabilities as developers write code.

#sdl#linter#security-linting
Stars998
Forks127
Last commit1 day ago
Agentic Radar
Agentic RadarPython

A security scanner that analyzes agentic AI workflows for vulnerabilities, visualizes their structure, and hardens system prompts.

#agentic-workflow#ai#agentic-ai
Stars998
Forks136
Last commit7 months ago
DevSkim
DevSkimC#

A security linting framework with IDE plugins and CLI tools that identifies vulnerabilities as developers write code.

#ide-plugin#sdl#linter
Stars998
Forks127
Last commit1 day ago
Gauntlt
GauntltRuby

A ruggedization framework for security testing that is usable by developers, operations, and security teams.

#attack-framework#ruggedization#bdd
Stars995
Forks186
Last commit4 years ago
regula
regulaOpen Policy Agent

Regula checks infrastructure as code templates for AWS, Azure, Google Cloud, and Kubernetes security and compliance using Open Policy Agent/Rego.

#rego#policy-as-code#kubernetes
Stars965
Forks113
Last commit1 year ago
pike
pikeHCL

Pike determines the minimum IAM permissions required to run OpenTofu/Terraform infrastructure code.

#bridgecrew#azure-iam#gcp-iam
Stars915
Forks45
Last commit3 days ago
lockfile-lint
lockfile-lintJavaScript

A security linter for npm and yarn lockfiles to detect malicious package injections and enforce trust policies.

#supply-chain-security#hacktoberfest#lockfile
Stars865
Forks36
Last commit27 days ago
BinSkim
BinSkimC#

A lightweight static analysis tool that validates security and correctness characteristics of Windows PE and Linux ELF binaries.

#nuget#microsoft#security-scanning
Stars855
Forks174
Last commit14 days ago
Common Threat Matrix for CI/CD Pipeline
Common Threat Matrix for CI/CD Pipeline

An ATT&CK-like threat matrix mapping adversary tactics and techniques specific to CI/CD pipeline security.

#supply-chain-security#infrastructure-security#security
Stars776
Forks88
Last commit1 month ago
krane
kraneRuby

A Kubernetes RBAC static analysis tool that identifies security risks and visualizes RBAC design.

#redisgraph#rbac#rbac-roles
Stars742
Forks34
Last commit5 months ago
GraphQL Cop
GraphQL CopPython

A lightweight Python utility for running common security tests against GraphQL APIs, ideal for CI/CD checks.

#graphql#penetration-testing#security
Stars677
Forks100
Last commit7 months ago
repo-supervisor
repo-supervisorJavaScript

A security tool that scans code for secrets and passwords in JSON, JavaScript, and YAML files via CLI or GitHub PR webhooks.

#github-integration#entropy-analysis#secret-detection
Stars654
Forks89
Last commit3 years ago
Snyk Test Action
Snyk Test ActionHTML

A collection of GitHub Actions for Snyk to check projects for vulnerabilities across multiple languages and tools.

#actions#container-security#snyk-integration
Stars644
Forks194
Last commit16 days ago
CI/CD Attacks
CI/CD Attacks

A curated collection of offensive security research, techniques, and tools for attacking CI/CD pipelines and software supply chains.

#cicd#attack-techniques#red-teaming
Stars610
Forks57
Last commit1 month ago
Scan code with SonarCloud
Scan code with SonarCloudShell

A deprecated GitHub Action for scanning code with SonarQube Cloud to detect quality and security issues.

#multi-language#sonarcloud#security-scanning
Stars608
Forks228
Last commit10 months ago
Docker Secure Deployment Guidelines
Docker Secure Deployment Guidelines

A deployment checklist for securely deploying Docker containers on Linux-based hosts.

#container-security#infrastructure-security#security-guidelines
Stars607
Forks79
Last commit9 years ago
coi
coiPython

A security-hardened container runtime for AI coding agents using Incus system containers with real-time threat detection and credential isolation.

#supply-chain-security#container-security#ai-coding-agents
Stars592
Forks49
Last commit3 days ago
Gato-X
Gato-XPython

A fast scanning and attack toolkit for identifying and exploiting GitHub Actions vulnerabilities at scale.

#python-tool#cicd#red-teaming
Stars561
Forks51
Last commit4 days ago
Insider CLI
Insider CLIGo

A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.

#multi-language#owasp#ios-security
Stars553
Forks80
Last commit4 years ago
Kubectrl Kubesec
Kubectrl KubesecGo

A kubectl plugin for security risk analysis of Kubernetes resources like pods, deployments, daemonsets, and statefulsets.

#container-security#kubectl-plugin#risk-analysis
Stars519
Forks36
Last commit1 year ago
Makes
MakesNix

A CI/CD framework powered by Nix for building secure and reproducible software supply chains.

#supply-chain-security#devops#aws-batch
Stars491
Forks45
Last commit10 months ago
Skylos
SkylosPython

Open-source static analysis tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and AI-generated regressions.

#security-scanning#ai-code-review#vulnerability-detection
Stars473
Forks23
Last commit1 day ago
threatcl
threatclGo

A DevOps-first CLI tool for documenting threat models using HashiCorp Configuration Language (HCL).

#security-documentation#graphql-api#data-flow-diagram
Stars463
Forks27
Last commit2 days ago
Puma Scan
Puma ScanC#

A Visual Studio extension for real-time .NET secure code analysis that displays vulnerabilities as compiler warnings.

#secure-coding#static-code-analysis#vulnerability-detection
Stars449
Forks78
Last commit2 days ago
k-rail
k-railGo

A Kubernetes admission controller that enforces security and reliability policies for workloads in multi-tenant clusters.

#admission-controller#workload-security#policy-enforcement
Stars440
Forks53
Last commit3 years ago
Awesome Kubernetes (K8s) Threat Detection
Awesome Kubernetes (K8s) Threat Detection

A curated list of resources for detecting threats and defending Kubernetes systems.

#container-security#cloud-native-security#security-hardening
Stars409
Forks43
Last commit2 years ago
Software Assurance Maturity Model
Software Assurance Maturity ModelJavaScript

A framework to help organizations formulate and implement a strategy for software security tailored to their specific risks.

#maturity-models#security#maturity-model
Stars401
Forks127
Last commit4 years ago
Managed Kubernetes Inspection Tool (MKIT)
Managed Kubernetes Inspection Tool (MKIT)Dockerfile

A security inspection tool for managed Kubernetes clusters that identifies common misconfigurations via Docker container and web UI.

#container-security#inspec#azure
Stars396
Forks25
Last commit4 years ago
Shisho
ShishoRust

A lightweight static analyzer for developers that finds code patterns across multiple programming languages.

#multi-language#developer-tools#terraform-security
Stars386
Forks13
Last commit2 years ago
Parse
ParsePHP

A static security scanner for PHP code that identifies potential vulnerabilities without executing the code.

#command-line-tool#vulnerability-detection#security
Stars382
Forks41
Last commit8 years ago
Credential Digger
Credential DiggerPython

A GitHub scanning tool that identifies hardcoded credentials and filters false positives using machine learning models.

#hardcoded-credentials#regex#vscode-extension
Stars366
Forks54
Last commit4 months ago
Nord Stream
Nord StreamPython

A tool for extracting secrets from CI/CD environments by deploying malicious pipelines, supporting Azure DevOps, GitHub, and GitLab.

#azure-devops#cicd#azuredevops
Stars366
Forks22
Last commit7 days ago
Progpilot
ProgpilotPHP

A static application security testing (SAST) tool for PHP that detects vulnerabilities like XSS through taint analysis.

#taint-analysis#static-code-analysis#code-security
Stars365
Forks65
Last commit11 months ago
Hawkeye
HawkeyeJavaScript

A security scanning CLI tool that detects vulnerabilities, secrets, and outdated dependencies across multiple programming languages.

#multi-language#pre-commit-hooks#secret-detection
Stars362
Forks86
Last commit4 years ago
PreviousPage 3 of 5Next

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
#Security86
#Static Analysis50
#Ci Cd38
#Security Tools35
#Cloud Security34
#Docker31
#Security Scanning30
#Vulnerability Detection27
#Aws25
#Infrastructure As Code25
#Container Security24
#Supply Chain Security21