Todas las etiquetas
Etiqueta del catálogo

#devsecops

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

61 registros
Con la etiqueta «devsecops»Ordenado por índice de salud
Go
88Excelenteíndice de salud
trufflesecurity/truffleHog
Find, verify, and analyze leaked credentials
Go★ 27K↓ 0/mes14 jul 2026
AGPL-3.014 jul 2026 · métricas 1.13.0
PyPI · npm
86Excelenteíndice de salud
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.1K↓ 50/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go
85Excelenteíndice de salud
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 57016 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
PyPI
82Buenoíndice de salud
bancolombia/devsecops-engine-tools
Toolchain for the evaluation of different devsecops practices
Python★ 45↓ 0/mes14 jul 2026
AGPL-3.014 jul 2026 · métricas 1.13.0
PyPI · npm
80Buenoíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
Maven
79Buenoíndice de salud
akto-api-security/akto
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure
Java · JavaScript★ 148915 jul 2026
MIT15 jul 2026 · métricas 1.13.0
PyPI
78Buenoíndice de salud
cisco-open/forge
ForgeMT is a multi-tenant platform for self-hosted GitHub Actions runners on AWS. It gives platform teams an IaC-driven way to operate ephemeral EC2 runners and ARC/Kubernetes runner scale sets for many tenant repositories.
HCL · Python★ 21021 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
PyPI · crates.io
78Buenoíndice de salud
mongodb/kingfisher
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. 1,000+ rules.
Rust★ 117419 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
77Buenoíndice de salud
mindburn-labs/helm-ai-kernel
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 5317 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
PyPI
77Buenoíndice de salud
pyupio/safety
Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.
Python★ 1992↓ 4.7M/mes21 jul 2026
Licencia propia21 jul 2026 · métricas 1.13.0
Go · npm
77Buenoíndice de salud
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 46417 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm · PyPI
76Buenoíndice de salud
bunkerity/bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Python · Shell · HTML★ 10.7K20 jul 2026
AGPL-3.020 jul 2026 · métricas 1.13.0
Go · Maven
76Buenoíndice de salud
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 63819 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
npm
75Buenoíndice de salud
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1266↓ 2624/mes23 jul 2026
AGPL-3.023 jul 2026 · métricas 1.13.0
Go
75Buenoíndice de salud
mindburn-labs/helm-oss
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 5318 jul 2026
Apache-2.018 jul 2026 · métricas 1.13.0
Go
74Buenoíndice de salud
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14617 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
PyPI
74Buenoíndice de salud
owasp/docksec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 46017 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go
72Buenoíndice de salud
l3montree-dev/flawfix
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14618 jul 2026
Licencia propia18 jul 2026 · métricas 1.13.0
npm
71Buenoíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2247/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go · PyPI
71Buenoíndice de salud
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 917 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
PyPI · npm
70Buenoíndice de salud
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript · JavaScript★ 39615 jul 2026
Licencia propia15 jul 2026 · métricas 1.13.0
PyPI
68Moderadoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm
68Moderadoíndice de salud
samartomar/ai-harness
Enterprise AI Bootstrapping Harness
TypeScript★ 4↓ 4137/mes18 jul 2026
Apache-2.018 jul 2026 · métricas 1.13.0
Go
67Moderadoíndice de salud
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 jul 2026
Apache-2.020 jul 2026 · métricas 1.13.0
PyPI
67Moderadoíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/mes14 jul 2026
Licencia propia14 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
cynative/cynative
Deep cybersecurity research agent for your cloud, code and runtime - ask your infrastructure anything. Read-only, sandboxed.
Go★ 8715 jul 2026
Apache-2.015 jul 2026 · métricas 1.13.0
Go · npm
66Moderadoíndice de salud
opt-nc/geol
Efficiently show and monitor end-of-life dates for a number of products in your terminal and CI using endoflife.date API
HTML · Go★ 1219 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
65Moderadoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
65Moderadoíndice de salud
kondukto-io/kdt
CLI to interact with Kondukto
Go★ 2915 jul 2026
GPL-3.015 jul 2026 · métricas 1.13.0