Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
-
Updated
May 20, 2026 - Shell
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
BigBang the product
Integrate SonarQube scanner to GitHub Actions
AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE ATT&CK, 11 languages, zero configuration.
Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayHub project contain one click docker-compose file which configure and run images from docker hub.
Helps you continuously monitor and fix common security vulnerabilities in your Django application.
A collection of technical and sales resources related to Prisma Cloud Compute and Prisma Cloud Enterprise created for the PANW Channel Partner Ecosystem and other engineers working with the solution
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about DevSecOps in Cybersecurity.
AI-powered security assessment SKILLS for your codebase. Multi-language (JS, Go, Python, Rust, Java, PHP, Ruby, C#). Works with Claude Code, Codex, OpenCode, etc.
Use @xonsh wherever you go through the SSH without installation on the host.
Git Anti-Virus Scan Action - Detect trojans, viruses, malware & other malicious threats.
This repo includes a demo that shows how a Kubernetes cluster can be hijacked and how to prevent it using common best practices.
OWASP EKS Goat is a deliberately vulnerable EKS cluster environment to explore AWS cloud-native security through hands-on attack and defense labs with walkthrough.
All that is required to run MobSF in the ci
Collection of roadmaps, tools, best practice, resources about DevSecOps
Gixposed is a powerful command-line tool designed to search the commit history of Git repositories for sensitive information, such as API keys and access tokens. Its purpose is to help developers and security professionals quickly identify and remediate exposed sensitive informations in their codebases.
A hands-on lab toolkit for container security, from CIS-benchmark fundamentals to architectural trust governance. 12 production-grade labs covering image hardening, signing, supply chain attestation, admission control, and runtime debugging. Built from real Fortune 500 cluster experience.
Medusa is an orchestration bash toolkit that deploys and manages 35 open source cybersecurity tools via an interactive menu or command line.
Add a description, image, and links to the devsecops topic page so that developers can more easily learn about it.
To associate your repository with the devsecops topic, visit your repo's landing page and select "manage topics."