11/12 free views
Documentation
Documentation
DevSecOps (not explicitly listed, closest fit: Governance, Risk, and Compliance (GRC))

DevSecOps

by sottlmarek

6.6Kstars
1.1Kforks
161watchers
Updated about 1 month ago
About

A comprehensive open-source library providing curated DevSecOps tools, methodologies, and resources to guide engineers in securing cloud-native development pipelines.

Ultimate DevSecOps library

Primary Use Case

This repository serves as a centralized knowledge base and guide for developers, security engineers, and DevOps practitioners looking to integrate security throughout the software development lifecycle. It helps users discover, evaluate, and adopt active open-source security tools and best practices tailored for DevSecOps environments, especially in cloud and infrastructure as code contexts.

Key Features
  • Curated list of active open-source DevSecOps security tools
  • Coverage of multiple security domains including secrets management, SAST, DAST, supply chain security, and infrastructure as code security
  • Categorization of tools by lifecycle phases such as pre-commit, build, deploy, and operate
  • Inclusion of methodologies, whitepapers, and architecture resources
  • Focus on cloud-native security across AWS, Azure, GCP, and multi-cloud environments
  • Contribution guidelines ensuring quality and relevance of added tools
  • Emphasis on security automation and developer/security experience integration
Security Frameworks
Reconnaissance
Resource Development
Defense Evasion
Execution
Persistence
Usage Insights
  • Integrate this library into CI/CD pipelines to automate security checks and enforce policy-as-code.
  • Use the curated tools to build a comprehensive DevSecOps security baseline tailored to multi-cloud environments.
  • Leverage the documentation to train development and security teams on secure coding and infrastructure practices.
  • Combine secrets management tools from the library with runtime monitoring for enhanced credential protection.
  • Adopt contribution guidelines to maintain high-quality, up-to-date security tooling knowledge for continuous improvement.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about DevSecOps. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

3 free chats per tool • Instant responses • No credit card

Security Profile
Red Team40%
Blue Team80%
Purple Team70%
Details
LicenseMIT License
Open Issues11
Topics
security
devops
devsecops
cloud
tool
aws
k8s
docker
awesome-list
azure