Todas las etiquetas
Etiqueta del catálogo

#devsecops

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

61 registros
Con la etiqueta «devsecops»Ordenado por índice de salud
Go
64Moderadoíndice de salud
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 221 jul 2026
BSD-3-Clause21 jul 2026 · métricas 1.13.0
Go
64Moderadoíndice de salud
glsec/glsec
GitLab CI security linter - find misconfigurations and vulnerabilities in .gitlab-ci.yml files
Go★ 1917 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go
63Moderadoíndice de salud
kondukto-io/cli
CLI to interact with Kondukto
Go★ 2915 jul 2026
GPL-3.015 jul 2026 · métricas 1.13.0
PyPI · npm
62Moderadoíndice de salud
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6171/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
61Moderadoíndice de salud
djadmin/fort
Audit and fix your Mac's security in one command. No agent, no signup, open source.
Go · HTML★ 72↓ 0/mes14 jul 2026
MIT14 jul 2026 · métricas 1.13.0
Go
61Moderadoíndice de salud
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 119 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
Go
60Moderadoíndice de salud
cfgaudit/cfgaudit
AI agent configuration security auditor - find misconfigurations in Claude Code, Cursor, and other AI tools
Go★ 6↓ 0/mes14 jul 2026
Apache-2.014 jul 2026 · métricas 1.13.0
npm
60Moderadoíndice de salud
this-is-securl/securl
SecURL - passive external security posture scanner. Free hosted scanner, open-source engine, CI integration
TypeScript · JavaScript★ 316 jul 2026
MIT16 jul 2026 · métricas 1.13.0
npm
59Moderadoíndice de salud
Vinay-O/slopscore
Scan your codebase for AI slop. Get a Slop Score. Ship clean. A zero-dependency CLI (85 detectors: security, performance, code-quality, design tells) + a 181-pattern Anti-Slop Protocol for AI coding agents.
JavaScript★ 2↓ 2121/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go
59Moderadoíndice de salud
plenoai/pleno-dlp
Unified DLP scanner for secrets and PII across filesystem, git, stdin, and SaaS sources.
Go★ 117 jul 2026
AGPL-3.017 jul 2026 · métricas 1.13.0
Hex
58Moderadoíndice de salud
aryaminus/controlkeel
Agent control plane for governed AI coding: validate changes, enforce policy gates, track findings, proofs, and evals based on your habits.
Elixir★ 1017 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go
58Moderadoíndice de salud
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 1.13.0
PyPI
58Moderadoíndice de salud
thothforge/thothctl
A command line interface tool designed for efficient management and automation within your internal developer platform.
Python★ 4↓ 5453/mes19 jul 2026
Licencia propia19 jul 2026 · métricas 1.13.0
Go · npm
57Moderadoíndice de salud
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 jul 2026
MIT19 jul 2026 · métricas 1.13.0
PyPI · crates.io · Maven +2
56Moderadoíndice de salud
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go
56Moderadoíndice de salud
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 015 jul 2026
Apache-2.015 jul 2026 · métricas 1.13.0
PyPI
55Moderadoíndice de salud
Mehrdoost/devsecops-radar
🛡️ Unify Trivy, Semgrep, Poutine & Zizmor scans into one AI-enhanced, offline-ready dashboard. Track CI/CD security trends, get LLM-powered analysis, and enforce policies — the open-source DevSecOps command center.
Python · JavaScript · HTML★ 117 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
Go
54Moderadoíndice de salud
jitpass/jit
jit is an open-source CLI that finds the plaintext secrets scattered across a Mac and converts them into just-in-time, Touch-ID-gated credentials, without breaking anything that reads them.
Go★ 215 jul 2026
Licencia propia15 jul 2026 · métricas 1.13.0
Go
54Moderadoíndice de salud
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 015 jul 2026
MIT15 jul 2026 · métricas 1.13.0
npm
53Moderadoíndice de salud
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2972/mes17 jul 2026
MIT17 jul 2026 · métricas 1.13.0
PyPI · npm
53Moderadoíndice de salud
wang-jie-git/moat
AI Coding Gatekeeper — Zero-config, real-time guardrails for AI-generated code. 零配置AI编码守门员,实时拦截架构/安全/回归问题。
Python · HTML★ 1↓ 2206/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 1.13.0
PyPI
52Moderadoíndice de salud
vishnu-77/secchecker
El repositorio no publica descripción.
Python★ 122 jul 2026
MIT22 jul 2026 · métricas 1.13.0
Go · PyPI
49En riesgoíndice de salud
Zayan-Mohamed/secscan
SecScan is a fast, configurable secret scanning tool written in Go that detects API keys, tokens, credentials, and high-entropy secrets across source code and full Git history. Built for developers and CI pipelines, with strong defaults and low false positives.
Go · Shell · PowerShell★ 420 jul 2026
MIT20 jul 2026 · métricas 1.13.0
Go
49En riesgoíndice de salud
rubysolo/envisible
Encrypt secrets inline in your config and .env files with ENC[…] markers — local keypair or GCP/AWS/Azure KMS. Safe to commit. Ships a setup skill for AI coding agents.
Go★ 117 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go
48En riesgoíndice de salud
wille/gh-actions-cli
Harden and manage your GitHub Actions: SHA-pin every action, enforce allowlist policies, update interactively, and analyze run health
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 1.13.0
PyPI
46En riesgoíndice de salud
TariqDreamsTech/ranbval-sdk
Secrets that refuse to be stolen. Sealed API keys that decrypt only on your allowlisted repo — and raise a security error if anything tries to print, iterate, or read them. Every access attempt alerts the owner.
Python★ 1↓ 2156/mes20 jul 2026
MIT20 jul 2026 · métricas 1.13.0
npm
43En riesgoíndice de salud
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 19↓ 5644/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go
41En riesgoíndice de salud
zuhayrb/dexpose
Pure-Go CLI that scans APK files for leaked secrets. Zero dependencies, gitleaks-compatible rules, CI-friendly exit codes.
Go★ 4↓ 0/mes14 jul 2026
MIT14 jul 2026 · métricas 1.13.0
Go
39En riesgoíndice de salud
fyfran/ironwall
8-step open-source security audit CLI. Secrets, SAST, dependency CVEs, IaC, supply chain. MIT. AI-assisted.
Go · Python★ 015 jul 2026
MIT15 jul 2026 · métricas 1.13.0
Go
38En riesgoíndice de salud
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 220 jul 2026
MIT20 jul 2026 · métricas 1.13.0