#devsecops (30 Repositories)
Ranked open-source repositories tagged with #devsecops, scored by pull request acceptance likelihood and maintainer engagement velocity.
72.1%
72.5h
30 repositories tagged #devsecops
cynative/cynative
Build your own security agents. Open-source framework for agents with live, read-only access to your infrastructure, with no path to widen it. Reasons across AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system.
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
hahwul/dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
ArduPilot/MethodicConfigurator
A clear ArduPilot configuration sequence
devsecblueprint/devsecblueprint
Learn DevSecOps and Cloud Security Engineering fundamentals.
awslabs/threat-designer
Threat Designer is a GenerativeAI application designed to automate and streamline the threat modeling process for secure system design.
duriantaco/skylos
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
SecObserve/SecObserve
SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It supports a variety of open source vulnerability scanners and integrates easily into CI/CD pipelines.
zaproxy/action-baseline
A GitHub Action for running the ZAP Baseline scan
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
zaproxy/action-full-scan
A GitHub Action for running the ZAP Full scan
safedep/vet
Protect against malicious open source packages 🤖
santhreal/keyhog
GPU-accelerated secret scanner for code, Git history, containers, cloud, browser assets, and CI. 923 detectors, live verification, CUDA, Metal, WGPU.
mongodb/kingfisher
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. Hundreds of rules.
openai/codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
betterleaks/betterleaks
Find leaked secrets everywhere.
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
openappsec/openappsec
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
gravitl/netmaker
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
AndrewDryga/emisar
An MCP that lets AI tools securely connect to your infrastructure, write IaaS code, debug issues, and assist during incidents - without risking production stability. Built for security teams to approve and infrastructure teams to experience like magic.
MustacheCase/zanadir
zanadir is an open-source CLI tool that analyzes GitHub repositories and suggests open-source tools to enhance CI/CD best practices.
project-copacetic/copacetic
🧵 CLI tool for directly patching container images!
lintsinghua/DeepAudit
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
DevOpsHiveHQ/dynamic-devops-roadmap
A FREE pragmatic DevOps learning to kickstart your DevOps career and knowledge in the Cloud Native era following the Agile MVP style! ⭐ (2026 plans for DevOps, Cloud, Platform, SRE, SWE)
trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials
reconmap/reconmap
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
gitleaks/gitleaks
Find secrets with Gitleaks 🔑
DoD-Platform-One/bigbang
BigBang the product