全部标签
目录标签

#devsecops

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

86 条记录
标签为“devsecops”按健康指数排序
PyPI · npm
84优秀健康指数
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Python★ 1,281↓ 10.9K/月2026年8月24日
MIT2026年8月24日 · 指标 2.10.0
PyPI
84优秀健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 502026年8月22日
自定义许可证2026年8月22日 · 指标 2.10.0
PyPI
83优秀健康指数
infobyte/faraday
Open Source Vulnerability Management Platform
Python★ 6,698↓ 917/月2026年8月29日
GPL-3.02026年8月29日 · 指标 2.10.0
Go
81优秀健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月23日
Apache-2.02026年7月23日 · 指标 2.10.0
Go
81优秀健康指数
cfgaudit/cfgaudit
AI agent configuration security auditor - find misconfigurations in Claude Code, Cursor, and other AI tools
Go★ 72026年8月23日
Apache-2.02026年8月23日 · 指标 2.10.0
npm
81优秀健康指数
samartomar/ai-harness
Enterprise AI Bootstrapping Harness
TypeScript★ 4↓ 4,137/月2026年7月18日
Apache-2.02026年7月18日 · 指标 2.10.0
PyPI
78良好健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
Go · npm
78良好健康指数
opt-nc/geol
Efficiently show and monitor end-of-life dates for a number of products in your terminal and CI using endoflife.date API
HTML · Go★ 122026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
Go
78良好健康指数
rezmoss/sbomlyze
git diff for your SBOM ,compare CycloneDX/SPDX/Syft bills of materials, detect tampering, and gate CI
Go★ 242026年7月20日
Apache-2.02026年7月20日 · 指标 2.10.0
PyPI
78良好健康指数
xeonvs/open-code-review-toolkit
GitLab CI integration toolkit for Open Code Review
Python★ 1↓ 2,646/月2026年8月26日
Apache-2.02026年8月26日 · 指标 2.10.0
Go
77良好健康指数
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 02026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
Go
77良好健康指数
jitpass/jit
Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 1572026年9月5日
自定义许可证2026年9月5日 · 指标 2.10.0
Go
77良好健康指数
kondukto-io/kdt
CLI to interact with Kondukto
Go★ 292026年7月15日
GPL-3.02026年7月15日 · 指标 2.10.0
Go
75良好健康指数
TomTonic/extract-sbom
Sandboxed SBOM extraction from arbitrary artifacts. Outputs traceability records and CycloneDX JSON for automation, auditability, and supply chain security.
Go★ 22026年7月21日
BSD-3-Clause2026年7月21日 · 指标 2.10.0
Go
75良好健康指数
glsec/glsec
GitLab CI security linter - find misconfigurations and vulnerabilities in .gitlab-ci.yml files
Go★ 192026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
npm · Go
73良好健康指数
HodeTech/Leakwatch
High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.
Go★ 2↓ 46/月2026年7月27日
MIT2026年7月27日 · 指标 2.10.0
Go
73良好健康指数
kondukto-io/cli
CLI to interact with Kondukto
Go★ 292026年7月15日
GPL-3.02026年7月15日 · 指标 2.10.0
PyPI
73良好健康指数
philpaz/recusal
Deterministic governance for Claude and MCP tool calls. Pin approved capabilities, detect drift, and refuse unsafe or unapproved actions before execution. No model in the decision path.
Python★ 3↓ 2,854/月2026年7月27日
Apache-2.02026年7月27日 · 指标 2.10.0
PyPI · npm
71良好健康指数
PrismorSec/prismor
Runtime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/月2026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
69良好健康指数
mukul975/Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Python★ 27.3K2026年8月5日
Apache-2.02026年8月5日 · 指标 2.10.0
Go
67良好健康指数
djadmin/fort
Audit and fix your Mac's security in one command. No agent, no signup, open source.
Go · HTML★ 782026年9月5日
MIT2026年9月5日 · 指标 2.10.0
Go
67良好健康指数
eitanity/kanonarion
Dependency assurance software for Go. A deterministic, local source of truth about your dependencies - what's in them, how they're licensed, how to call them, and which known vulnerabilities your code actually reaches. Developers query it from the CLI with human-readable output; AI coding agents get JSON.
Go★ 12026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
PyPI
67良好健康指数
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 22026年7月31日
MIT2026年7月31日 · 指标 2.10.0
npm
67良好健康指数
this-is-securl/securl
SecURL - passive external security posture scanner. Free hosted scanner, open-source engine, CI integration
TypeScript · JavaScript★ 32026年7月16日
MIT2026年7月16日 · 指标 2.10.0
Go
67良好健康指数
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 22026年8月28日
MIT2026年8月28日 · 指标 2.10.0
Go
65良好健康指数
plenoai/pleno-dlp
Unified DLP scanner for secrets and PII across filesystem, git, stdin, and SaaS sources.
Go★ 12026年7月17日
AGPL-3.02026年7月17日 · 指标 2.10.0
Go
63中等健康指数
famclaw/honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 32026年7月17日
MIT2026年7月17日 · 指标 2.10.0
Go
63中等健康指数
idriss-eliguene/landlock-genprof
Automatic Kubernetes security profile generator — Landlock, NetworkPolicy, seccomp, and Linux capabilities — built on observation of a running pod, not manual rule authoring.
Go · Shell★ 32026年9月2日
Apache-2.02026年9月2日 · 指标 2.10.0
Hex
62中等健康指数
aryaminus/controlkeel
Agent control plane for governed AI coding: validate changes, enforce policy gates, track findings, proofs, and evals based on your habits.
Elixir★ 102026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
Go
62中等健康指数
kanywst/brtc
Cost calculator for offline password brute-force attacks: time + USD per GPU profile, with a CI gatekeeper.
Go★ 02026年7月26日
MIT2026年7月26日 · 指标 2.10.0