Todas las etiquetas
Etiqueta del catálogo

#devsecops

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

86 registros
Con la etiqueta «devsecops»Ordenado por índice de salud
PyPI · npm
84Excelenteíndice de salud
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1281↓ 10.9K/mes24 ago 2026
MIT24 ago 2026 · métricas 2.10.0
PyPI
84Excelenteíndice de salud
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 5022 ago 2026
Licencia propia22 ago 2026 · métricas 2.10.0
PyPI
83Excelenteíndice de salud
infobyte/faraday
Open Source Vulnerability Management Platform
Python★ 6698↓ 917/mes29 ago 2026
GPL-3.029 ago 2026 · métricas 2.10.0
Go
81Excelenteíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823 jul 2026
Apache-2.023 jul 2026 · métricas 2.10.0
Go
81Excelenteíndice de salud
cfgaudit/cfgaudit
AI agent configuration security auditor - find misconfigurations in Claude Code, Cursor, and other AI tools
Go★ 723 ago 2026
Apache-2.023 ago 2026 · métricas 2.10.0
npm
81Excelenteíndice de salud
samartomar/ai-harness
Enterprise AI Bootstrapping Harness
TypeScript★ 4↓ 4137/mes18 jul 2026
Apache-2.018 jul 2026 · métricas 2.10.0
PyPI
78Buenoíndice de salud
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1928/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
Go · npm
78Buenoíndice de salud
opt-nc/geol
Efficiently show and monitor end-of-life dates for a number of products in your terminal and CI using endoflife.date API
HTML · Go★ 1219 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go
78Buenoíndice de salud
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 2420 jul 2026
Apache-2.020 jul 2026 · métricas 2.10.0
PyPI
78Buenoíndice de salud
xeonvs/open-code-review-toolkit
GitLab CI integration toolkit for Open Code Review
Python★ 1↓ 2646/mes26 ago 2026
Apache-2.026 ago 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 019 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 1575 sept 2026
Licencia propia5 sept 2026 · métricas 2.10.0
Go
77Buenoíndice de salud
kondukto-io/kdt
CLI to interact with Kondukto
Go★ 2915 jul 2026
GPL-3.015 jul 2026 · métricas 2.10.0
Go
75Buenoíndice de salud
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 jul 2026
BSD-3-Clause21 jul 2026 · métricas 2.10.0
Go
75Buenoíndice de salud
glsec/glsec
GitLab CI security linter - find misconfigurations and vulnerabilities in .gitlab-ci.yml files
Go★ 1917 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
npm · Go
73Buenoíndice de salud
HodeTech/Leakwatch
High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.
Go★ 2↓ 46/mes27 jul 2026
MIT27 jul 2026 · métricas 2.10.0
Go
73Buenoíndice de salud
kondukto-io/cli
CLI to interact with Kondukto
Go★ 2915 jul 2026
GPL-3.015 jul 2026 · métricas 2.10.0
PyPI
73Buenoíndice de salud
philpaz/recusal
Deterministic governance for Claude and MCP tool calls. Pin approved capabilities, detect drift, and refuse unsafe or unapproved actions before execution. No model in the decision path.
Python★ 3↓ 2854/mes27 jul 2026
Apache-2.027 jul 2026 · métricas 2.10.0
PyPI · npm
71Buenoíndice de salud
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6171/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
69Buenoíndice de salud
mukul975/Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Python★ 27.3K5 ago 2026
Apache-2.05 ago 2026 · métricas 2.10.0
Go
67Buenoíndice de salud
djadmin/fort
Audit and fix your Mac's security in one command. No agent, no signup, open source.
Go · HTML★ 785 sept 2026
MIT5 sept 2026 · métricas 2.10.0
Go
67Buenoíndice de salud
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 119 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
PyPI
67Buenoíndice de salud
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 231 jul 2026
MIT31 jul 2026 · métricas 2.10.0
npm
67Buenoíndice de salud
this-is-securl/securl
SecURL - passive external security posture scanner. Free hosted scanner, open-source engine, CI integration
TypeScript · JavaScript★ 316 jul 2026
MIT16 jul 2026 · métricas 2.10.0
Go
67Buenoíndice de salud
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 228 ago 2026
MIT28 ago 2026 · métricas 2.10.0
Go
65Buenoíndice de salud
plenoai/pleno-dlp
Unified DLP scanner for secrets and PII across filesystem, git, stdin, and SaaS sources.
Go★ 117 jul 2026
AGPL-3.017 jul 2026 · métricas 2.10.0
Go
63Moderadoíndice de salud
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 2.10.0
Go
63Moderadoíndice de salud
idriss-eliguene/landlock-genprof
Automatic Kubernetes security profile generator — Landlock, NetworkPolicy, seccomp, and Linux capabilities — built on observation of a running pod, not manual rule authoring.
Go · Shell★ 32 sept 2026
Apache-2.02 sept 2026 · métricas 2.10.0
Hex
62Moderadoíndice de salud
aryaminus/controlkeel
Agent control plane for governed AI coding: validate changes, enforce policy gates, track findings, proofs, and evals based on your habits.
Elixir★ 1017 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
Go
62Moderadoíndice de salud
kanywst/brtc
Cost calculator for offline password brute-force attacks: time + USD per GPU profile, with a CI gatekeeper.
Go★ 026 jul 2026
MIT26 jul 2026 · métricas 2.10.0