Devsecops Open Source Projects

Browse 158 Devsecops open source projects, ranked by GitHub stars. Find the most popular Devsecops tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 158 projects
36,990 stars

aquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Metrics details
Stars36,990
28,211 stars

gitleaks/gitleaks

Find secrets with Gitleaks 🔑

Metrics details
Stars28,211
27,115 stars

trufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

Metrics details
Stars27,115
21,462 stars

MobSF/Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Metrics details
Stars21,462
14,317 stars

prowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Metrics details
Stars14,317
11,692 stars

gravitl/netmaker

Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.

Metrics details
Stars11,692
10,733 stars

bunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Metrics details
Stars10,733
8,992 stars

We5ter/Scanners-Box

A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

Metrics details
Stars8,992
8,730 stars

firezone/firezone

Enterprise-ready zero-trust access platform built on WireGuard®.

Metrics details
Stars8,730
7,892 stars

turbot/steampipe

Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.

Metrics details
Stars7,892
7,023 stars

aquasecurity/tfsec

Tfsec is now part of Trivy

Metrics details
Stars7,023
6,803 stars

sottlmarek/DevSecOps

Ultimate DevSecOps library

Metrics details
Stars6,803
6,660 stars

infobyte/faraday

Open Source Vulnerability Management Platform

Metrics details
Stars6,660
5,719 stars

madhuakula/kubernetes-goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

Metrics details
Stars5,719
5,427 stars

devsecops/awesome-devsecops

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Metrics details
Stars5,427
5,303 stars

deepfence/ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP)

Metrics details
Stars5,303
5,213 stars

tenable/terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Metrics details
Stars5,213
5,130 stars

hahwul/dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

Metrics details
Stars5,130
4,843 stars

DefectDojo/django-DefectDojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Metrics details
Stars4,843
4,022 stars

DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Metrics details
Stars4,022
3,370 stars

deepfence/SecretScanner

:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:

Metrics details
Stars3,370
3,064 stars

ContainerSSH/ContainerSSH

ContainerSSH: Launch containers on demand

Metrics details
Stars3,064
2,975 stars

baidu/openrasp

🔥Open source RASP solution

Metrics details
Stars2,975
2,705 stars

Bearer/bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Metrics details
Stars2,705
2,673 stars

Checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Metrics details
Stars2,673
2,568 stars

ajinabraham/nodejsscan

nodejsscan is a static security code scanner for Node.js applications.

Metrics details
Stars2,568
2,468 stars

archerysec/archerysec

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Metrics details
Stars2,468
2,447 stars

DevOpsHiveHQ/dynamic-devops-roadmap

A FREE pragmatic DevOps learning to kickstart your DevOps career and knowledge in the Cloud Native era following the Agile MVP style! ⭐ (2026 plans for DevOps, Cloud, Platform, SRE, SWE)

Metrics details
Stars2,447
2,376 stars

joseadanof/awesome-cloudnative-trainings

Awesome Trainings from Cloud Native Computing Foundation Projects and Kubernetes related software

Metrics details
Stars2,376
2,339 stars

praetorian-inc/noseyparker

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Metrics details
Stars2,339
2,279 stars

cider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Metrics details
Stars2,279
2,144 stars

hahwul/DevSecOps

♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎

Metrics details
Stars2,144
2,109 stars

tom0li/collection-document

Collection of quality safety articles. Awesome articles.

Metrics details
Stars2,109
2,046 stars

6mile/DevSecOps-Playbook

This is a step-by-step guide to implementing a DevSecOps program for any size organization

Metrics details
Stars2,046
1,973 stars

ahmedtariq01/Cloud-DevOps-Learning-Resources

This repo includes Books and imp notes related to GCP, Azure, AWS, Docker, K8s, and DevOps. More, exam and interview prep notes.

Metrics details
Stars1,973
1,971 stars

GitGuardian/ggshield

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.

Metrics details
Stars1,971
1,784 stars

ASTTeam/CodeQL

《深入理解CodeQL》Finding vulnerabilities with CodeQL.

Metrics details
Stars1,784
1,773 stars

hysnsec/awesome-threat-modelling

A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.

Metrics details
Stars1,773
1,735 stars

intel/cve-bin-tool

The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 200 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

Metrics details
Stars1,735
1,703 stars

TaptuIT/awesome-devsecops

Curating the best DevSecOps resources and tooling.

Metrics details
Stars1,703
1,680 stars

project-copacetic/copacetic

🧵 CLI tool for directly patching container images!

Metrics details
Stars1,680
1,652 stars

openappsec/openappsec

open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.

Metrics details
Stars1,652
1,620 stars

krol3/container-security-checklist

Checklist for container security - devsecops practices

Metrics details
Stars1,620
1,492 stars

akto-api-security/akto

Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure

Metrics details
Stars1,492
1,468 stars

lunasec-io/lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

Metrics details
Stars1,468
1,451 stars

OWASP/wrongsecrets

Vulnerable app with examples showing how to not use secrets

Metrics details
Stars1,451
1,375 stars

aquasecurity/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Metrics details
Stars1,375
1,352 stars

noir-cr/noir

Attack surface detector that identifies endpoints by static analysis

Metrics details
Stars1,352
1,320 stars

deepfence/YaraHunter

🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍

Metrics details
Stars1,320
1,303 stars

bridgecrewio/terragoat

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

Metrics details
Stars1,303
1,266 stars

owasp-dep-scan/dep-scan

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

Metrics details
Stars1,266
1,115 stars

XmirrorSecurity/OpenSCA-cli

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

Metrics details
Stars1,115
1,093 stars

safedep/vet

Protect against malicious open source packages 🤖

Metrics details
Stars1,093
1,081 stars

OWASP/DevSecOpsGuideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Metrics details
Stars1,081
1,075 stars

ajinabraham/CMSScan

CMS Scanner: Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues

Metrics details
Stars1,075
1,044 stars

jonrau1/ElectricEye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

Metrics details
Stars1,044
1,036 stars

guardrailsio/awesome-php-security

Awesome PHP Security Resources 🕶🐘🔐

Metrics details
Stars1,036
985 stars

secureCodeBox/secureCodeBox

secureCodeBox (SCB) - continuous secure delivery out of the box

Metrics details
Stars985
965 stars

satan1a/awesome-cybersecurity-blueteam-cn

网络安全 · 攻防对抗 · 蓝队清单,中文版

Metrics details
Stars965
941 stars

reconmap/reconmap

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.

Metrics details
Stars941
1-60 of 158 projects
Get A Weekly Email With Trending Devsecops Projects
Stay updated on Devsecops plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.