Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure
-
Updated
Feb 21, 2025 - Java
Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure
DevSecOps Project using git, GitHub, jenkins, Maven,Junit, SonarQube, Docker, Trivy, Hashicorp Vault, AWS, Kubernetes
🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍
Code examples for the AWS Security Blog post: How to use CI/CD to deploy and configure AWS security services with Terraform
A demo of cloud-native Inner Loop and Outer Loop controlling a 2-tier app (Python + Go) with Red Hat OpenShift using Tekton Pipelines, Argo CD GitOps, Eclipse Che aka OpenShift DevSpaces and Quay.io registry
SBOM quality score - Quality metrics for your sboms
Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayHub project contain one click docker-compose file which configure and run images from docker hub.
CLI component of OWASP PurpleTeam
The workshop guide sources. The rendered website can be found here : https://devsecops-workshop.github.io/
Quickly get a GitLab network up and running. The network consists of a GitLab server, docker-in-docker compatible GitLab runners, and SonarQube
Application Security pipelines
🔍 Seccomp profiling and function-level tracing tool.
Comprehensive set of Terraform coding standards designed for enterprise-level projects
La intención de la workshop es mostrar y orientar a los equipos de desarrollo, seguridad y devops (entre otros) que quieran comenzar en DevSecOps, a segurar sus aplicaciones o bien a conocer un poco más acerca del desarrollo seguro, para esto, estaremos otorgando algunos tips e información que fuimos aprendiendo para armar un Pipeline DevSecOps …
Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayBackend project contains source code of backend with all plugin integrations writer in Spring Boot.
Orchestrator component of OWASP PurpleTeam
Example of how to integrate Threagile into GitHub workflows
Add a description, image, and links to the devsecops-pipeline topic page so that developers can more easily learn about it.
To associate your repository with the devsecops-pipeline topic, visit your repo's landing page and select "manage topics."