-
Updated
Sep 30, 2020 - Python
#
devsecops
Here are 201 public repositories matching this topic...
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
python
rest
static-analysis
apk
owasp
dynamic-analysis
web-security
ipa
malware-analysis
mobsf
android-security
mobile-security
windows-mobile-security
ios-security
mobile-security-framework
api-testing
cwe
devsecops
cvssv2
runtime-security
Collaborative Penetration Test and Vulnerability Management Platform
security
devops
chatops
security-audit
collaboration
orchestration
nmap
penetration-testing
vulnerability
infosec
pentesting
collaborative
cve
nessus
vulnerability-management
vulnerability-scanners
burpsuite
security-automation
devsecops
continuous-scanning
-
Updated
Sep 10, 2020 - JavaScript
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
-
Updated
Sep 7, 2020
nodejsscan is a static security code scanner for Node.js applications.
nodejs
javascript
security
node
static-analysis
code-analysis
code-review
security-scanner
devsecops
sast
node-security
-
Updated
Oct 1, 2020 - CSS
Centralize Vulnerability Assessment and Management for DevSecOps Team
devops
opensource
pentesting
vulnerabilities
devops-tools
scanning
vulnerability-management
vulnerability-assessment
secdevops
pentesters
devsecops
-
Updated
Sep 30, 2020 - HTML
DefectDojo is an open-source application vulnerability correlation and security orchestration tool.
python
kubernetes
security
automation
django
analytics
owasp
helm-charts
vulnerability-databases
vulnerability-management
security-orchestration
security-automation
devsecops
vulnerability-correlation
-
Updated
Oct 1, 2020 - HTML
CMS Scanner: Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues
-
Updated
Jul 30, 2020 - CSS
Detect secret in source code, scan your repo for leaks. Find secrets with GitGuardian and prevent leaked credentials. GitGuardian is an automated secrets detection & remediation service.
-
Updated
Oct 1, 2020 - Python
Awesome PHP Security Resources 🕶 🐘 🔐
-
Updated
Mar 9, 2019
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
infrastructure
aws
security
devops
terraform
architecture
infrastructure-as-code
security-tools
cloudsecurity
devsecops
cloud-security
terrascan
security-violations
-
Updated
Oct 1, 2020 - Go
Dependency-Track is an intelligent Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components.
security
owasp
bom
vulnerabilities
vulndb
appsec
component-analysis
nvd
vulnerability-detection
sca
software-security
security-automation
devsecops
software-composition-analysis
bill-of-materials
ossindex
purl
package-url
sbom
cyclonedx
-
Updated
Sep 29, 2020 - Java
kube-scan: Octarine k8s cluster risk assessment tool
kubernetes
security
devops
security-audit
k8s
cloud-native
security-scanner
security-tools
devsecops
security-scanners
-
Updated
Sep 12, 2020 - Go
Open
Document ZAP
1
omerlh
opened
May 9, 2018
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
-
Updated
Sep 18, 2020 - HCL
Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)
-
Updated
Jun 1, 2020 - Python
Identify vulnerabilities in running containers, images, hosts and repositories
github
docker
kubernetes
jenkins
devops
circleci
gitlab
serverless
secops
cloud-native
security-vulnerability
vulnerability-management
threat-analysis
security-tools
devsecops
vulnerability-scanning
compliance-automation
registry-scanning
-
Updated
Sep 28, 2020 - HCL
Knowledge seeks no man
linux
docker
kubernetes
aws
devops
cloud
containers
site-reliability-engineering
gcp
gke
infrastructure-as-code
sre
information-security
devsecops
-
Updated
Aug 16, 2020
GitGuardian Shield GitHub Action - Find exposed credentials in your commits
-
Updated
Jul 10, 2020 - Dockerfile
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
awesome
awesome-list
threat-modeling
appsec
devsecops
security-review
practical-devsecops
devsecops-university
-
Updated
Sep 30, 2020 - Dockerfile
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
xss
vulnerability
infosec
application-security
interview-questions
appsec
webappsec
sdlc
devsecops
security-team
security-engineer-interview
-
Updated
Aug 7, 2020
PaulSec
commented
Sep 28, 2020
Hi,
It would be interesting to have those new rules integrated in ChopChop, see : https://github.com/nnposter/nndefaccts/blob/master/http-default-accounts-fingerprints-nndefaccts.lua
The Secure Coding Framework
-
Updated
Aug 18, 2020 - TypeScript
docker
devops
container
secops
cybersecurity
penetration-testing
infosec
pentesting
pentest
cyber-security
it-security
devsecops
pentest-tool
docker-security
container-hardening
container-security
-
Updated
Sep 19, 2018
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration
-
Updated
Jul 12, 2020 - Python
prabhu
commented
Jul 9, 2020
It will be a fun exercise to make scan work for mono repos such as https://github.com/swapnil-linux/spring-boot-examples
In theory, this can be achieved using a bit of bash with the new scan AppImage.
Kubernetes Common Configuration Scoring System
-
Updated
Apr 23, 2020 - TypeScript
Improve this page
Add a description, image, and links to the devsecops topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the devsecops topic, visit your repo's landing page and select "manage topics."