All tags
Catalogue tag

#devsecops

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

86 records
Tagged “devsecops”Ranked by health index
PyPI · npm
84Excellenthealth index
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1,281↓ 10.9K/moAug 24, 2026
MITAug 24, 2026 · metrics 2.10.0
PyPI
84Excellenthealth index
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 50Aug 22, 2026
Custom licenseAug 22, 2026 · metrics 2.10.0
PyPI
83Excellenthealth index
infobyte/faraday
Open Source Vulnerability Management Platform
Python★ 6,698↓ 917/moAug 29, 2026
GPL-3.0Aug 29, 2026 · metrics 2.10.0
Go
81Excellenthealth index
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 23, 2026
Apache-2.0Jul 23, 2026 · metrics 2.10.0
Go
81Excellenthealth index
cfgaudit/cfgaudit
AI agent configuration security auditor - find misconfigurations in Claude Code, Cursor, and other AI tools
Go★ 7Aug 23, 2026
Apache-2.0Aug 23, 2026 · metrics 2.10.0
npm
81Excellenthealth index
samartomar/ai-harness
Enterprise AI Bootstrapping Harness
TypeScript★ 4↓ 4,137/moJul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 2.10.0
PyPI
78Goodhealth index
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
Go · npm
78Goodhealth index
opt-nc/geol
Efficiently show and monitor end-of-life dates for a number of products in your terminal and CI using endoflife.date API
HTML · Go★ 12Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
Go
78Goodhealth index
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 24Jul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 2.10.0
PyPI
78Goodhealth index
xeonvs/open-code-review-toolkit
GitLab CI integration toolkit for Open Code Review
Python★ 1↓ 2,646/moAug 26, 2026
Apache-2.0Aug 26, 2026 · metrics 2.10.0
Go
77Goodhealth index
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 0Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
Go
77Goodhealth index
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 157Sep 5, 2026
Custom licenseSep 5, 2026 · metrics 2.10.0
Go
77Goodhealth index
kondukto-io/kdt
CLI to interact with Kondukto
Go★ 29Jul 15, 2026
GPL-3.0Jul 15, 2026 · metrics 2.10.0
Go
75Goodhealth index
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 2Jul 21, 2026
BSD-3-ClauseJul 21, 2026 · metrics 2.10.0
Go
75Goodhealth index
glsec/glsec
GitLab CI security linter - find misconfigurations and vulnerabilities in .gitlab-ci.yml files
Go★ 19Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
npm · Go
73Goodhealth index
HodeTech/Leakwatch
High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.
Go★ 2↓ 46/moJul 27, 2026
MITJul 27, 2026 · metrics 2.10.0
Go
73Goodhealth index
kondukto-io/cli
CLI to interact with Kondukto
Go★ 29Jul 15, 2026
GPL-3.0Jul 15, 2026 · metrics 2.10.0
PyPI
73Goodhealth index
philpaz/recusal
Deterministic governance for Claude and MCP tool calls. Pin approved capabilities, detect drift, and refuse unsafe or unapproved actions before execution. No model in the decision path.
Python★ 3↓ 2,854/moJul 27, 2026
Apache-2.0Jul 27, 2026 · metrics 2.10.0
PyPI · npm
71Goodhealth index
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/moJul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
69Goodhealth index
mukul975/Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Python★ 27.3KAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
Go
67Goodhealth index
djadmin/fort
Audit and fix your Mac's security in one command. No agent, no signup, open source.
Go · HTML★ 78Sep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
Go
67Goodhealth index
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 1Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
PyPI
67Goodhealth index
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 2Jul 31, 2026
MITJul 31, 2026 · metrics 2.10.0
npm
67Goodhealth index
this-is-securl/securl
SecURL - passive external security posture scanner. Free hosted scanner, open-source engine, CI integration
TypeScript · JavaScript★ 3Jul 16, 2026
MITJul 16, 2026 · metrics 2.10.0
Go
67Goodhealth index
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 2Aug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
Go
65Goodhealth index
plenoai/pleno-dlp
Unified DLP scanner for secrets and PII across filesystem, git, stdin, and SaaS sources.
Go★ 1Jul 17, 2026
AGPL-3.0Jul 17, 2026 · metrics 2.10.0
Go
63Moderatehealth index
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
63Moderatehealth index
idriss-eliguene/landlock-genprof
Automatic Kubernetes security profile generator — Landlock, NetworkPolicy, seccomp, and Linux capabilities — built on observation of a running pod, not manual rule authoring.
Go · Shell★ 3Sep 2, 2026
Apache-2.0Sep 2, 2026 · metrics 2.10.0
Hex
62Moderatehealth index
aryaminus/controlkeel
Agent control plane for governed AI coding: validate changes, enforce policy gates, track findings, proofs, and evals based on your habits.
Elixir★ 10Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
Go
62Moderatehealth index
kanywst/brtc
Cost calculator for offline password brute-force attacks: time + USD per GPU profile, with a CI gatekeeper.
Go★ 0Jul 26, 2026
MITJul 26, 2026 · metrics 2.10.0