全部标签
目录标签

#devsecops

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

61 条记录
标签为“devsecops”按健康指数排序
Go
88优秀健康指数
trufflesecurity/truffleHog
Find, verify, and analyze leaked credentials
Go★ 27K↓ 0/月2026年7月14日
AGPL-3.02026年7月14日 · 指标 1.13.0
PyPI · npm
86优秀健康指数
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.1K↓ 50/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Go
85优秀健康指数
chainloop-dev/chainloop
SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 5702026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
PyPI
82良好健康指数
bancolombia/devsecops-engine-tools
Toolchain for the evaluation of different devsecops practices
Python★ 45↓ 0/月2026年7月14日
AGPL-3.02026年7月14日 · 指标 1.13.0
PyPI · npm
80良好健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
Maven
79良好健康指数
akto-api-security/akto
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure
Java · JavaScript★ 1,4892026年7月15日
MIT2026年7月15日 · 指标 1.13.0
PyPI
78良好健康指数
cisco-open/forge
ForgeMT is a multi-tenant platform for self-hosted GitHub Actions runners on AWS. It gives platform teams an IaC-driven way to operate ephemeral EC2 runners and ARC/Kubernetes runner scale sets for many tenant repositories.
HCL · Python★ 2102026年7月21日
Apache-2.02026年7月21日 · 指标 1.13.0
PyPI · crates.io
78良好健康指数
mongodb/kingfisher
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. 1,000+ rules.
Rust★ 1,1742026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
Go
77良好健康指数
mindburn-labs/helm-ai-kernel
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 532026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
PyPI
77良好健康指数
pyupio/safety
Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.
Python★ 1,992↓ 4.7M/月2026年7月21日
自定义许可证2026年7月21日 · 指标 1.13.0
Go · npm
77良好健康指数
safedep/pmg
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 4642026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
npm · PyPI
76良好健康指数
bunkerity/bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Python · Shell · HTML★ 10.7K2026年7月20日
AGPL-3.02026年7月20日 · 指标 1.13.0
Go · Maven
76良好健康指数
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 6382026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
npm
75良好健康指数
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/月2026年7月23日
AGPL-3.02026年7月23日 · 指标 1.13.0
Go
75良好健康指数
mindburn-labs/helm-oss
Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 532026年7月18日
Apache-2.02026年7月18日 · 指标 1.13.0
Go
74良好健康指数
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 1462026年7月17日
自定义许可证2026年7月17日 · 指标 1.13.0
PyPI
74良好健康指数
owasp/docksec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 4602026年7月17日
MIT2026年7月17日 · 指标 1.13.0
Go
72良好健康指数
l3montree-dev/flawfix
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 1462026年7月18日
自定义许可证2026年7月18日 · 指标 1.13.0
npm
71良好健康指数
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0
Go · PyPI
71良好健康指数
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 92026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
PyPI · npm
70良好健康指数
hashgraph-online/hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript · JavaScript★ 3962026年7月15日
自定义许可证2026年7月15日 · 指标 1.13.0
PyPI
68中等健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
npm
68中等健康指数
samartomar/ai-harness
Enterprise AI Bootstrapping Harness
TypeScript★ 4↓ 4,137/月2026年7月18日
Apache-2.02026年7月18日 · 指标 1.13.0
Go
67中等健康指数
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 242026年7月20日
Apache-2.02026年7月20日 · 指标 1.13.0
PyPI
67中等健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/月2026年7月14日
自定义许可证2026年7月14日 · 指标 1.13.0
Go
66中等健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月21日
Apache-2.02026年7月21日 · 指标 1.13.0
Go
66中等健康指数
cynative/cynative
Deep cybersecurity research agent for your cloud, code and runtime - ask your infrastructure anything. Read-only, sandboxed.
Go★ 872026年7月15日
Apache-2.02026年7月15日 · 指标 1.13.0
Go · npm
66中等健康指数
opt-nc/geol
Efficiently show and monitor end-of-life dates for a number of products in your terminal and CI using endoflife.date API
HTML · Go★ 122026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
Go
65中等健康指数
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 02026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
Go
65中等健康指数
kondukto-io/kdt
CLI to interact with Kondukto
Go★ 292026年7月15日
GPL-3.02026年7月15日 · 指标 1.13.0