There are 4 repositories under devsecops-pipeline topic.
🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍
Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure
SBOM quality score - Quality metrics for your sboms
CLI component of OWASP PurpleTeam
Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayHub project contain one click docker-compose file which configure and run images from docker hub.
Code examples for the AWS Security Blog post: How to use CI/CD to deploy and configure AWS security services with Terraform
DevSecOps pipeline for Python based project using Jenkins, Ansible, AWS, and open-source security tools and checks.
DevSecOps Project using git, GitHub, jenkins, Maven,Junit, SonarQube, Docker, Trivy, Hashicorp Vault, AWS, Kubernetes
Application Security pipelines
Efficient DevSecOps
A set of Gitlab pipelines and Github workflows to automate and ease on BugBounty and Penetration Testing engagements
All of our GitHub Actions rolled into one. Or as we like to say: One GitHub Action to rule them all!
Using PyRaider You can scan installed dependencies known security vulnerabilities. It uses publicly known exploits, vulnerabilities database.
SBOM Grep - search through SBOMs
La intención de la workshop es mostrar y orientar a los equipos de desarrollo, seguridad y devops (entre otros) que quieran comenzar en DevSecOps, a segurar sus aplicaciones o bien a conocer un poco más acerca del desarrollo seguro, para esto, estaremos otorgando algunos tips e información que fuimos aprendiendo para armar un Pipeline DevSecOps básico.
Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayBackend project contains source code of backend with all plugin integrations writer in Spring Boot.
GitHub action to run Threagile, the agile threat modeling toolkit, on a repo's threagile.yaml file
A demo of cloud-native Inner Loop and Outer Loop controlling a 2-tier app (Python + Go) with Red Hat OpenShift using Tekton Pipelines, Argo CD GitOps, Eclipse Che aka OpenShift DevSpaces and Quay.io registry
TLS scanning component of OWASP PurpleTeam
Example of how to integrate Threagile into GitHub workflows
The workshop guide sources. The rendered website can be found here : https://devsecops-workshop.github.io/
Infrastructure as Code for SUTs
Orchestrator component of OWASP PurpleTeam
Server scanning component of OWASP PurpleTeam
Repository shows a self-contained example of how to run trivy in your Tekton CI/CD Pipeline.
Logging component of OWASP PurpleTeam
Stage Two containers of OWASP PurpleTeam
DevSecOps pipeline for Python based web app using Jenkins, Ansible, AWS, and open-source security tools and checks.
Gitlab CI jobs stdout secrets finder
Demonstration of security in CI/CD pipelines using NGINX App Protect
Use 'Makefile.sec + Docker' to run security tests in CI/CD pipelines.
OWASP Secure Pipeline Verification Standard