全部标签
目录标签

#devsecops

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

86 条记录
标签为“devsecops”按健康指数排序
PyPI · npm
99卓越健康指数
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.7K↓ 217.7K/月2026年8月27日
Apache-2.02026年8月27日 · 指标 2.10.0
Go
99卓越健康指数
trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials
Go★ 27.4K2026年8月13日
AGPL-3.02026年8月13日 · 指标 2.10.0
Go
98卓越健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
PyPI
96卓越健康指数
bancolombia/devsecops-engine-tools
Toolchain for the evaluation of different devsecops practices
Python · TypeScript★ 42↓ 4,913/月2026年9月5日
AGPL-3.02026年9月5日 · 指标 2.10.0
PyPI
95卓越健康指数
GitGuardian/ggshield
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Python★ 1,9852026年8月13日
MIT2026年8月13日 · 指标 2.10.0
PyPI
95卓越健康指数
xonsh/xonsh
🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly.
Python★ 9,5992026年8月12日
自定义许可证2026年8月12日 · 指标 2.10.0
npm · PyPI
94卓越健康指数
bunkerity/bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Python · HTML · JavaScript★ 10.9K2026年8月28日
AGPL-3.02026年8月28日 · 指标 2.10.0
PyPI · npm
94卓越健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
PyPI
93卓越健康指数
cisco-open/forge
ForgeMT is a multi-tenant platform for self-hosted GitHub Actions runners on AWS. It gives platform teams an IaC-driven way to operate ephemeral EC2 runners and ARC/Kubernetes runner scale sets for many tenant repositories.
HCL · Python★ 2102026年7月21日
Apache-2.02026年7月21日 · 指标 2.10.0
PyPI · crates.io · npm
93卓越健康指数
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/月2026年9月5日
Apache-2.02026年9月5日 · 指标 2.10.0
Go
93卓越健康指数
mindburn-labs/helm-ai-kernel
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 532026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
PyPI · crates.io
93卓越健康指数
mongodb/kingfisher
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. 1,000+ rules.
Rust★ 1,1742026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
Go · npm
92优秀健康指数
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 4642026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
npm
91优秀健康指数
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/月2026年7月23日
AGPL-3.02026年7月23日 · 指标 2.10.0
91优秀健康指数
aquasecurity/trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
Shell · Makefile★ 1,3892026年8月1日
Apache-2.02026年8月1日 · 指标 2.10.0
Go · Maven
91优秀健康指数
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 6382026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
Go
90优秀健康指数
cynative/cynative
Open-source framework for security agents with live, read-only access to your infrastructure. Audit AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system for privilege escalation, public exposure, leaked credentials and more, with agents you write in one markdown file.
Go · Shell★ 1972026年9月5日
Apache-2.02026年9月5日 · 指标 2.10.0
Go
90优秀健康指数
mindburn-labs/helm-oss
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 532026年7月18日
Apache-2.02026年7月18日 · 指标 2.10.0
PyPI
90优秀健康指数
pyupio/safety
Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.
Python★ 1,995↓ 4.5M/月2026年8月27日
自定义许可证2026年8月27日 · 指标 2.10.0
89优秀健康指数
owasp-noir/noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
Crystal★ 1,3632026年8月4日
MIT2026年8月4日 · 指标 2.10.0
PyPI
89优秀健康指数
owasp/docksec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 4602026年7月17日
MIT2026年7月17日 · 指标 2.10.0
npm
88优秀健康指数
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/月2026年9月6日
MIT2026年9月6日 · 指标 2.10.0
Go
88优秀健康指数
betterleaks/betterleaks
Find leaked secrets everywhere.
Go★ 1,7292026年8月20日
MIT2026年8月20日 · 指标 2.10.0
PyPI
88优秀健康指数
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 72026年7月31日
自定义许可证2026年7月31日 · 指标 2.10.0
Go
88优秀健康指数
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 1462026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
Go
87优秀健康指数
l3montree-dev/flawfix
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 1462026年7月18日
自定义许可证2026年7月18日 · 指标 2.10.0
Go
86优秀健康指数
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 02026年7月24日
Apache-2.02026年7月24日 · 指标 2.10.0
Go · PyPI
86优秀健康指数
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 92026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
npm
86优秀健康指数
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/月2026年7月25日
MIT2026年7月25日 · 指标 2.10.0
PyPI
86优秀健康指数
stephrobert/dsoxlab
DevSecOps XL Labs — a domain-agnostic CLI framework to drive hands-on learning labs across multiple repositories
Python★ 55↓ 3,355/月2026年7月27日
Apache-2.02026年7月27日 · 指标 2.10.0