Devsecops Open Source Projects
Browse 158 Devsecops open source projects, ranked by GitHub stars. Find the most popular Devsecops tools and libraries.
aquasecurity/trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Metrics details
| Stars | 36,990 |
gitleaks/gitleaks
Find secrets with Gitleaks 🔑
Metrics details
| Stars | 28,211 |
trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials
Metrics details
| Stars | 27,115 |
MobSF/Mobile-Security-Framework-MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Metrics details
| Stars | 21,462 |
prowler-cloud/prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Metrics details
| Stars | 14,317 |
gravitl/netmaker
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
Metrics details
| Stars | 11,692 |
bunkerity/bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Metrics details
| Stars | 10,733 |
We5ter/Scanners-Box
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Metrics details
| Stars | 8,992 |
firezone/firezone
Enterprise-ready zero-trust access platform built on WireGuard®.
Metrics details
| Stars | 8,730 |
turbot/steampipe
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
Metrics details
| Stars | 7,892 |
aquasecurity/tfsec
Tfsec is now part of Trivy
Metrics details
| Stars | 7,023 |
sottlmarek/DevSecOps
Ultimate DevSecOps library
Metrics details
| Stars | 6,803 |
infobyte/faraday
Open Source Vulnerability Management Platform
Metrics details
| Stars | 6,660 |
madhuakula/kubernetes-goat
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Metrics details
| Stars | 5,719 |
devsecops/awesome-devsecops
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
Metrics details
| Stars | 5,427 |
deepfence/ThreatMapper
Open Source Cloud Native Application Protection Platform (CNAPP)
Metrics details
| Stars | 5,303 |
tenable/terrascan
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
Metrics details
| Stars | 5,213 |
hahwul/dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Metrics details
| Stars | 5,130 |
DefectDojo/django-DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
Metrics details
| Stars | 4,843 |
DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Metrics details
| Stars | 4,022 |
deepfence/SecretScanner
:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
Metrics details
| Stars | 3,370 |
ContainerSSH/ContainerSSH
ContainerSSH: Launch containers on demand
Metrics details
| Stars | 3,064 |
baidu/openrasp
🔥Open source RASP solution
Metrics details
| Stars | 2,975 |
Bearer/bearer
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Metrics details
| Stars | 2,705 |
Checkmarx/kics
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Metrics details
| Stars | 2,673 |
ajinabraham/nodejsscan
nodejsscan is a static security code scanner for Node.js applications.
Metrics details
| Stars | 2,568 |
archerysec/archerysec
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
Metrics details
| Stars | 2,468 |
DevOpsHiveHQ/dynamic-devops-roadmap
A FREE pragmatic DevOps learning to kickstart your DevOps career and knowledge in the Cloud Native era following the Agile MVP style! ⭐ (2026 plans for DevOps, Cloud, Platform, SRE, SWE)
Metrics details
| Stars | 2,447 |
joseadanof/awesome-cloudnative-trainings
Awesome Trainings from Cloud Native Computing Foundation Projects and Kubernetes related software
Metrics details
| Stars | 2,376 |
praetorian-inc/noseyparker
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
Metrics details
| Stars | 2,339 |
cider-security-research/cicd-goat
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
Metrics details
| Stars | 2,279 |
hahwul/DevSecOps
♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎
Metrics details
| Stars | 2,144 |
tom0li/collection-document
Collection of quality safety articles. Awesome articles.
Metrics details
| Stars | 2,109 |
6mile/DevSecOps-Playbook
This is a step-by-step guide to implementing a DevSecOps program for any size organization
Metrics details
| Stars | 2,046 |
ahmedtariq01/Cloud-DevOps-Learning-Resources
This repo includes Books and imp notes related to GCP, Azure, AWS, Docker, K8s, and DevOps. More, exam and interview prep notes.
Metrics details
| Stars | 1,973 |
GitGuardian/ggshield
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Metrics details
| Stars | 1,971 |
ASTTeam/CodeQL
《深入理解CodeQL》Finding vulnerabilities with CodeQL.
Metrics details
| Stars | 1,784 |
hysnsec/awesome-threat-modelling
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
Metrics details
| Stars | 1,773 |
intel/cve-bin-tool
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 200 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Metrics details
| Stars | 1,735 |
TaptuIT/awesome-devsecops
Curating the best DevSecOps resources and tooling.
Metrics details
| Stars | 1,703 |
project-copacetic/copacetic
🧵 CLI tool for directly patching container images!
Metrics details
| Stars | 1,680 |
openappsec/openappsec
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
Metrics details
| Stars | 1,652 |
krol3/container-security-checklist
Checklist for container security - devsecops practices
Metrics details
| Stars | 1,620 |
akto-api-security/akto
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure
Metrics details
| Stars | 1,492 |
lunasec-io/lunasec
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
Metrics details
| Stars | 1,468 |
OWASP/wrongsecrets
Vulnerable app with examples showing how to not use secrets
Metrics details
| Stars | 1,451 |
aquasecurity/trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
Metrics details
| Stars | 1,375 |
noir-cr/noir
Attack surface detector that identifies endpoints by static analysis
Metrics details
| Stars | 1,352 |
deepfence/YaraHunter
🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍
Metrics details
| Stars | 1,320 |
bridgecrewio/terragoat
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Metrics details
| Stars | 1,303 |
owasp-dep-scan/dep-scan
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
Metrics details
| Stars | 1,266 |
XmirrorSecurity/OpenSCA-cli
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
Metrics details
| Stars | 1,115 |
safedep/vet
Protect against malicious open source packages 🤖
Metrics details
| Stars | 1,093 |
OWASP/DevSecOpsGuideline
The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.
Metrics details
| Stars | 1,081 |
ajinabraham/CMSScan
CMS Scanner: Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues
Metrics details
| Stars | 1,075 |
jonrau1/ElectricEye
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
Metrics details
| Stars | 1,044 |
guardrailsio/awesome-php-security
Awesome PHP Security Resources 🕶🐘🔐
Metrics details
| Stars | 1,036 |
secureCodeBox/secureCodeBox
secureCodeBox (SCB) - continuous secure delivery out of the box
Metrics details
| Stars | 985 |
satan1a/awesome-cybersecurity-blueteam-cn
网络安全 · 攻防对抗 · 蓝队清单,中文版
Metrics details
| Stars | 965 |
reconmap/reconmap
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
Metrics details
| Stars | 941 |
