Todas las etiquetas
Etiqueta del catálogo

#devsecops

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

86 registros
Con la etiqueta «devsecops»Ordenado por índice de salud
Go · npm
62Moderadoíndice de salud
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 jul 2026
MIT19 jul 2026 · métricas 2.10.0
PyPI
62Moderadoíndice de salud
thothforge/thothctl
A command line interface tool designed for efficient management and automation within your internal developer platform.
Python★ 4↓ 5453/mes19 jul 2026
Licencia propia19 jul 2026 · métricas 2.10.0
Go
59Moderadoíndice de salud
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 015 jul 2026
Apache-2.015 jul 2026 · métricas 2.10.0
npm
57Moderadoíndice de salud
Vinay-O/slopscore
Scan your codebase for AI slop. Get a Slop Score. Ship clean. A zero-dependency CLI (85 detectors: security, performance, code-quality, design tells) + a 181-pattern Anti-Slop Protocol for AI coding agents.
JavaScript★ 2↓ 221/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
PyPI · crates.io · Maven +2
57Moderadoíndice de salud
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
PyPI
56Moderadoíndice de salud
Mehrdoost/devsecops-radar
🛡️ Unify Trivy, Semgrep, Poutine & Zizmor scans into one AI-enhanced, offline-ready dashboard. Track CI/CD security trends, get LLM-powered analysis, and enforce policies — the open-source DevSecOps command center.
Python · JavaScript · HTML★ 117 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
Go
56Moderadoíndice de salud
sairintechnologycom/pkgsafe
Supply-chain firewall for AI coding agents and developers — checks npm/PyPI packages against OSV advisories, typosquat & lifecycle-script heuristics, and your policy before install. Local-first, MCP-native.
Go★ 015 jul 2026
MIT15 jul 2026 · métricas 2.10.0
PyPI
54Moderadoíndice de salud
Akunimal/AI-Router-Blocker-AiO
Open-source DevSecOps gateway for AI traffic. Intercept, audit, and route LLM requests to prevent data leaks and enforce zero-trust security policies.
Python★ 126 jul 2026
Licencia propia26 jul 2026 · métricas 2.10.0
npm
54Moderadoíndice de salud
sudoeren/arhus
local-first security analysis for TypeScript & JavaScript
TypeScript★ 6↓ 2972/mes17 jul 2026
MIT17 jul 2026 · métricas 2.10.0
PyPI · npm
54Moderadoíndice de salud
wang-jie-git/moat
AI Coding Gatekeeper — Zero-config, real-time guardrails for AI-generated code. 零配置AI编码守门员,实时拦截架构/安全/回归问题。
Python · HTML★ 1↓ 2206/mes19 jul 2026
Apache-2.019 jul 2026 · métricas 2.10.0
Go
53Moderadoíndice de salud
opscart/opscart-k8s-watcher
Kubernetes operational triage dashboard. Surfaces CrashLoops, security gaps, orphaned resources, and cost waste — tells you what to fix first. Read-only, no agents, no cloud credentials.
Go · HTML★ 1120 ago 2026
MIT20 ago 2026 · métricas 2.10.0
npm
51Moderadoíndice de salud
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 20↓ 3215/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
PyPI
51Moderadoíndice de salud
vishnu-77/secchecker
El repositorio no publica descripción.
Python★ 122 jul 2026
MIT22 jul 2026 · métricas 2.10.0
Go · PyPI
48Débilíndice de salud
Zayan-Mohamed/secscan
SecScan is a fast, configurable secret scanning tool written in Go that detects API keys, tokens, credentials, and high-entropy secrets across source code and full Git history. Built for developers and CI pipelines, with strong defaults and low false positives.
Go · Shell · PowerShell★ 420 jul 2026
MIT20 jul 2026 · métricas 2.10.0
Go
48Débilíndice de salud
rubysolo/envisible
Encrypt secrets inline in your config and .env files with ENC[…] markers — local keypair or GCP/AWS/Azure KMS. Safe to commit. Ships a setup skill for AI coding agents.
Go★ 117 jul 2026
MIT17 jul 2026 · métricas 2.10.0
RubyGems
47Débilíndice de salud
OWASP/www-project-eks-goat
OWASP EKS Goat is a deliberately vulnerable EKS cluster environment to explore AWS cloud-native security through hands-on attack and defense labs with walkthrough.
Shell · Python★ 464 ago 2026
GPL-3.04 ago 2026 · métricas 2.10.0
Go
47Débilíndice de salud
wille/gh-actions-cli
Harden and manage your GitHub Actions: SHA-pin every action, enforce allowlist policies, update interactively, and analyze run health
Go★ 317 jul 2026
MIT17 jul 2026 · métricas 2.10.0
PyPI
44Débilíndice de salud
TariqDreamsTech/ranbval-sdk
Secrets that refuse to be stolen. Sealed API keys that decrypt only on your allowlisted repo — and raise a security error if anything tries to print, iterate, or read them. Every access attempt alerts the owner.
Python★ 1↓ 2156/mes20 jul 2026
MIT20 jul 2026 · métricas 2.10.0
Go
42Débilíndice de salud
malandas/andas
Sift real security risk from the noise — a cross-platform CLI that live-validates leaked secrets and reachability-ranks npm/Yarn vulnerabilities, so you fix what's actually exploitable.
Go★ 06 ago 2026
MIT6 ago 2026 · métricas 2.10.0
Go
42Débilíndice de salud
zuhayrb/dexpose
Pure-Go CLI that scans APK files for leaked secrets. Zero dependencies, gitleaks-compatible rules, CI-friendly exit codes.
Go★ 85 sept 2026
MIT5 sept 2026 · métricas 2.10.0
Go
36Débilíndice de salud
FYFran/ironwall
8-step open-source security audit CLI. Secrets, SAST, dependency CVEs, IaC, supply chain. MIT. AI-assisted.
Java · HTML★ 06 sept 2026
MIT6 sept 2026 · métricas 2.10.0
Go
33En riesgoíndice de salud
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 220 jul 2026
MIT20 jul 2026 · métricas 2.10.0
npm
28En riesgoíndice de salud
react-atomic/modality
El repositorio no publica descripción.
TypeScript★ 0↓ 10K/mes17 jul 2026
Sin licencia17 jul 2026 · métricas 2.10.0
21En riesgoíndice de salud
PortSwigger/dastardly-github-action
Runs a scan using Dastardly by Burp Suite against a target site and creates a JUnit XML report for the scan on completion.
Dockerfile★ 2964 ago 2026
Sin licencia4 ago 2026 · métricas 2.10.0
PyPI
19Críticoíndice de salud
FuzzingLabs/secpipe
MCP server for AI-driven security pipelines
Python★ 8034 ago 2026
Licencia propia4 ago 2026 · métricas 2.10.0
PyPI
17Críticoíndice de salud
dmdhrumilmistry/offat
Tests your API automatically for common API vulnerabilities. Project is still Work In Progress. PRs are appreciated.
Python★ 347 ago 2026
MIT7 ago 2026 · métricas 2.10.0