dogear

enter for all results · esc to close

DevSecOps

147 items from taptuit/awesome-devsecops ★1,745

  1. 0
    Trivy github.com

    Aqua Security's open source simple and comprehensive vulnerability scanner for containers (suitable for CI).

  2. 0
    bridgecrewio/checkov :fire::fire::fire::fire::fire: github.com

    Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

  3. 0
    blackbox github.com

    Safely store secrets in a VCS repo using GPG

  4. 0
    sops github.com

    An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.

  5. 0
    Deepfence Threat Mapper github.com

    Powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

  6. 0
    official OWASP ZAP github.com

    OWASP - An open-source web application vulnerability scanner, including an API for CI/CD integration.

  7. 0
    KICS github.com

    An infrastructure-as-code scanning tool, find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle. Can be extended for additional policies.

  8. 0
    Brakeman github.com

    A gem to scan code against security vulnerabilities. :red_circle:

  9. 0
    Gitleaks github.com

    A SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos.

  10. 0
    Grype github.com

    A vulnerability scanner for container images, filesystems and SBOMs.

  11. 0
    Hadolint github.com

    A Dockerfile linter that checks for best practices, common mistakes, and is also able to lint any bash written in RUN instructions;.

  12. 0
    Docker bench security github.com

    The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

  13. 0
    syft github.com

    A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

  14. 0
    bandit github.com

    Python Code Quality Authority - Find common security vulnerabilities in Python code.

  15. 0
    gopass github.com

    Gopass - Password manager for teams relying on Git and gpg. Manages secrets in encrypted files and repositories.

  16. 0
    trufflehog github.com

    💸 Searches through Git repositories for high entropy strings and secrets, digging deep into commit history.

  17. 0
    Git Secrets github.com

    Amazon AWS - Scan git repositories for secrets committed within code or commit messages.

  18. 0
    Clair github.com

    Clair is an open source project for the static analysis of vulnerabilities in appc and docker containers.

  19. 0
    OWASP NodeGoat github.com

    OWASP - A Node.js web application that demonstrates and provides ways to address common security vulnerabilities.

  20. 0
    detect-secrets github.com

    An enterprise friendly way of detecting and preventing secrets in code. It does this by running periodic diff outputs against heuristically crafted regex statements, to identify whether any new secret has been committed. This way, it avoids the overhead of digging through all…

  21. 0
    DevSkim github.com

    Regex-based static analysis tool for Visual Studio, VS Code, and Sublime Text - C/C++, C#, PHP, ASP, Python, Ruby, Java, and others.

  22. 0
    Teller github.com

    a secrets management tool for devops and developers - manage secrets across multiple vaults and keystores from a single place.

  23. 0
    RESTler (⭐2.9k) github.com

    A stateful REST API fuzzing tool that automatically discovers security and reliability bugs by intelligently inferring producer-consumer dependencies from OpenAPI specifications.

  24. 0
    cicd-goat github.com

    Cider Security - A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

  25. 0
    Golang Security Checker github.com

    securego - CLI tool to scan Go code for potential security flaws.

  26. 0
    credstash github.com

    Store secrets using AWS KMS and DynamoDB

  27. 0
    Keyscope github.com

    Keyscope is an extensible key and secret validation for checking active secrets against multiple SaaS vendors built in Rust

  28. 0
    Netz github.com

    Discover internet-wide misconfigurations, using zgrab2 and others.

  29. 0
    Tfsec github.com

    Liam Galvin - Scan Terraform templates for security misconfiguration and noncompliance with AWS, Azure and GCP security best practice.

  30. 0
    Kubernetes Goat github.com

    Madhu Akula - Intentionally vulnerable cluster environment to learn and practice Kubernetes security.

  31. next page of items loading…