awesome-devsecops
by JakobTheDev
A curated collection of the best DevSecOps resources and tools to enhance security automation, vulnerability scanning, and infrastructure as code security.
Curating the best DevSecOps resources and tooling.
Primary Use Case
This repository serves as a comprehensive guide for developers, security engineers, and DevOps professionals looking to integrate security into their development pipelines. It provides curated resources and tooling recommendations to streamline security automation, vulnerability detection, and infrastructure security practices within DevSecOps workflows.
- Curated list of top DevSecOps tools and resources
- Focus on security automation
- Includes vulnerability scanners
- Covers infrastructure as code security
- Regularly updated to reflect best practices
- Supports a broad range of security domains within DevSecOps
- Integrate curated tools into CI/CD pipelines for continuous security validation and automated vulnerability detection.
- Use as a knowledge base to train development and security teams on best practices in DevSecOps.
- Leverage infrastructure as code security tools to prevent misconfigurations before deployment.
- Combine with automated scanning tools to enable early detection of vulnerabilities during development.
- Facilitate purple team exercises by aligning offensive and defensive toolsets and workflows from the curated resources.
Docs Take 2 Hours. AI Takes 10 Seconds.
Ask anything about awesome-devsecops. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.
This tool hasn't been indexed yet. Request indexing to enable AI chat.
Admin will review your request within 24 hours
Related Tools

earthly
earthly/earthly
Super simple build framework with fast, repeatable builds and an instantly familiar syntax – like Dockerfile and Makefile had a baby.

pull
wei/pull
🤖 Keep your forks up-to-date via automated PRs

jx
jenkins-x/jx
Jenkins X provides automated CI+CD for Kubernetes with Preview Environments on Pull Requests using Cloud Native pipelines from Tekton

zizmor
zizmorcore/zizmor
Static analysis for GitHub Actions

garden
garden-io/garden
Automation for Kubernetes development and testing. Spin up production-like environments for development, testing, and CI on demand. Use the same configuration and workflows at every step of the process. Speed up your builds and test runs via shared result caching

okteto
okteto/okteto
Develop your applications directly in your Kubernetes Cluster
