devsecops
Here are 418 public repositories matching this topic...
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
-
Updated
Mar 22, 2022 - JavaScript
config validation
Is your feature request related to a problem? Please describe.
It would be nice if gitleaks had a validate command that would validate examples found in the config rules. Introducing such a feature would speed up rule development and help with debugging.
Describe the solution you'd like
example entry in the rules tables
ex:
[[rules]]
id = "discord-client-secret"
desProwler is an Open Source security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It contains more than 200 controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks.
-
Updated
Mar 22, 2022 - Shell
Security scanner for your Terraform code
-
Updated
Mar 21, 2022 - Go
Describe the issue
I wouldn't expect to get the alert if not defined explicitly.
Examples
https://github.com/hashicorp/terraform-provider-google/releases/tag/v4.0.0
Version (please complete the following information):
- Checkov Version 2.0.780
It seems we have already removed the following lines from the docker-compose reference.
volumes:
- /var/run/dbus/system_bus_socket:/var/run/dbus/system_bus_socket
- /run/systemd/system:/run/systemd/system
- /etc/systemd/system:/etc/systemd/system
- /sys/fs/cgroup:/sys/fs/cgroup
cap_add:
- SYS_ADMIN
But we are still seeing them in the following f
Collaborative Penetration Test and Vulnerability Management Platform
-
Updated
Mar 14, 2022 - Python
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
-
Updated
Mar 18, 2022
- terrascan version: 1.9.0
- terraform version: 1.0.1
Enhancement Request
Other security scanning tools (e.g. checkov and tfsec) have a --soft-fail flag or equivalent option that allows you to always exit with 0 status.
Extremely useful when running the tool without halting a pipeline for example.
I currently use a workaround, but something more concrete would be very desira
-
Updated
Mar 20, 2022 - Python
Ultimate DevSecOps library
-
Updated
Mar 9, 2022
Slack us first!
Hello. I write about problem here:
https://owasp.slack.com/archives/C2P5BA8MN/p1624892081234100
Be informative
As additional into slack I find the same behaviour with Risk Accepted findings. Into Metrics I see 0 Risk Accepted findings, but I have 1 Risk Accepted finding
Bug description
No error. Metrics into product, or metrics dushboard has incorrect info
nodejsscan is a static security code scanner for Node.js applications.
-
Updated
Feb 20, 2022 - CSS
Kubernetes Goat
-
Updated
Feb 14, 2022 - HTML
Centralize Vulnerability Assessment and Management for DevSecOps Team
-
Updated
Mar 22, 2022 - Python
-
Updated
Mar 21, 2022 - Go
WireGuard®-based VPN server and firewall
-
Updated
Mar 18, 2022 - Elixir
-
Updated
Mar 22, 2022 - JavaScript
Find secrets and passwords in container images and file systems
-
Updated
Mar 21, 2022 - Python
The current swagger definition is autogenerated. The automatically generated definitions rely on reflection and annotations to create the documentation. The reflection capabilities are poor at best and lead to missing API parameters. Annotations can help in some cases, but the only fix for Swagger is to create individual POJOs for every possible request. This will lead to unnecessary large number
Checklist for container security - devsecops practices
-
Updated
Mar 22, 2022
CMS Scanner: Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues
-
Updated
May 18, 2021 - CSS
Is your feature request related to a problem? Please describe.
when ggshield does not detect secret and the verbose mode is not set, there is no output and the cli only returns a zero no error code. Although it is compliant with linux tool philosophy, it is not always clear for our users / customers that the scanning was successful and that there are no leaks.
**Describe the solution you'
LunaSec - Open Source AppSec platform that automatically notifies you the next time vulnerabilities like Log4Shell or node-ipc happen. Track your dependencies and builds in a centralized service. Get started in one-click via our GitHub App or host it yourself.
-
Updated
Mar 22, 2022 - TypeScript
Awesome PHP Security Resources
-
Updated
Sep 22, 2021
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
-
Updated
Mar 21, 2022 - HCL
kube-scan: Octarine k8s cluster risk assessment tool
-
Updated
Mar 15, 2022 - Go
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
-
Updated
Nov 24, 2021 - Dockerfile
Improve this page
Add a description, image, and links to the devsecops topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the devsecops topic, visit your repo's landing page and select "manage topics."


Container scanning schemas below 14.0.0 have been deprecated.
blob/main/contrib/gitlab.tpl:3is using a deprecated version:The latest version of the schema is [14.1.0](https://gitlab.com/gitlab-org/gitla