devsecops topic
kics
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
steampipe
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
ContainerSSH
ContainerSSH: Launch containers on demand
hunter
Hunter作为中通DevSecOps闭环方案中的一环,扮演着很重要的角色,开源之后希望能帮助到更多企业。
makes
A software supply chain framework powered by Nix.
preflight
preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.
Pentest-In-Docker
Docker image to exploit RCE, try for pentest methods and test container security solutions (trivy, falco and etc.)
purify
All-in-one tool for managing vulnerability reports from AppSec pipelines
vals-operator
Kubernetes Operator to sync secrets between different secret backends and Kubernetes
yatas
:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration