Todas las etiquetas
Etiqueta del catálogo

#devsecops

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

86 registros
Con la etiqueta «devsecops»Ordenado por índice de salud
PyPI · npm
99Excepcionalíndice de salud
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.7K↓ 217.7K/mes27 ago 2026
Apache-2.027 ago 2026 · métricas 2.10.0
Go
99Excepcionalíndice de salud
trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials
Go★ 27.4K13 ago 2026
AGPL-3.013 ago 2026 · métricas 2.10.0
Go
98Excepcionalíndice de salud
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
PyPI
96Excepcionalíndice de salud
bancolombia/devsecops-engine-tools
Toolchain for the evaluation of different devsecops practices
Python · TypeScript★ 42↓ 4913/mes5 sept 2026
AGPL-3.05 sept 2026 · métricas 2.10.0
PyPI
95Excepcionalíndice de salud
GitGuardian/ggshield
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Python★ 198513 ago 2026
MIT13 ago 2026 · métricas 2.10.0
PyPI
95Excepcionalíndice de salud
xonsh/xonsh
🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly.
Python★ 959912 ago 2026
Licencia propia12 ago 2026 · métricas 2.10.0
npm · PyPI
94Excepcionalíndice de salud
bunkerity/bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Python · HTML · JavaScript★ 10.9K28 ago 2026
AGPL-3.028 ago 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
PyPI
93Excepcionalíndice de salud
cisco-open/forge
ForgeMT is a multi-tenant platform for self-hosted GitHub Actions runners on AWS. It gives platform teams an IaC-driven way to operate ephemeral EC2 runners and ARC/Kubernetes runner scale sets for many tenant repositories.
HCL · Python★ 21021 jul 2026
Apache-2.021 jul 2026 · métricas 2.10.0
PyPI · crates.io · npm
93Excepcionalíndice de salud
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/mes5 sept 2026
Apache-2.05 sept 2026 · métricas 2.10.0
Go
93Excepcionalíndice de salud
mindburn-labs/helm-ai-kernel
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 5317 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI · crates.io
93Excepcionalíndice de salud
mongodb/kingfisher
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. 1,000+ rules.
Rust★ 117419 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go · npm
92Excelenteíndice de salud
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
npm
91Excelenteíndice de salud
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1266↓ 2624/mes23 jul 2026
AGPL-3.023 jul 2026 · métricas 2.10.0
91Excelenteíndice de salud
aquasecurity/trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
Shell · Makefile★ 13891 ago 2026
Apache-2.01 ago 2026 · métricas 2.10.0
Go · Maven
91Excelenteíndice de salud
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 63819 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go
90Excelenteíndice de salud
cynative/cynative
Open-source framework for security agents with live, read-only access to your infrastructure. Audit AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system for privilege escalation, public exposure, leaked credentials and more, with agents you write in one markdown file.
Go · Shell★ 1975 sept 2026
Apache-2.05 sept 2026 · métricas 2.10.0
Go
90Excelenteíndice de salud
mindburn-labs/helm-oss
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 5318 jul 2026
Apache-2.018 jul 2026 · métricas 2.10.0
PyPI
90Excelenteíndice de salud
pyupio/safety
Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.
Python★ 1995↓ 4.5M/mes27 ago 2026
Licencia propia27 ago 2026 · métricas 2.10.0
89Excelenteíndice de salud
owasp-noir/noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
Crystal★ 13634 ago 2026
MIT4 ago 2026 · métricas 2.10.0
PyPI
89Excelenteíndice de salud
owasp/docksec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 46017 jul 2026
MIT17 jul 2026 · métricas 2.10.0
npm
88Excelenteíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5893/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
Go
88Excelenteíndice de salud
betterleaks/betterleaks
Find leaked secrets everywhere.
Go★ 172920 ago 2026
MIT20 ago 2026 · métricas 2.10.0
PyPI
88Excelenteíndice de salud
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 731 jul 2026
Licencia propia31 jul 2026 · métricas 2.10.0
Go
88Excelenteíndice de salud
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14617 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
Go
87Excelenteíndice de salud
l3montree-dev/flawfix
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14618 jul 2026
Licencia propia18 jul 2026 · métricas 2.10.0
Go
86Excelenteíndice de salud
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 024 jul 2026
Apache-2.024 jul 2026 · métricas 2.10.0
Go · PyPI
86Excelenteíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
npm
86Excelenteíndice de salud
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/mes25 jul 2026
MIT25 jul 2026 · métricas 2.10.0
PyPI
86Excelenteíndice de salud
stephrobert/dsoxlab
DevSecOps XL Labs — a domain-agnostic CLI framework to drive hands-on learning labs across multiple repositories
Python★ 55↓ 3355/mes27 jul 2026
Apache-2.027 jul 2026 · métricas 2.10.0