Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
-
Updated
Aug 19, 2026 - Shell
DevSecOps is the practice of seamlessly integrating security practices into every phase of the software development lifecycle, from initial design through integration, testing, deployment, and delivery. It emphasizes building robust security checks directly into continuous integration and continuous delivery (CI/CD) pipelines, utilizing automated security scanning, and ensuring rigorous dependency management to mitigate vulnerabilities early.
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE ATT&CK, 11 languages, zero configuration.
BigBang the product
Integrate SonarQube scanner to GitHub Actions
Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayHub project contain one click docker-compose file which configure and run images from docker hub.
🚀 DevSecOps intro elective — 10 hands-on labs + 2 bonus hardening OWASP Juice Shop: threat modeling (STRIDE/Threagile), signed commits & secret scanning, SBOM/SCA, SAST + DAST, IaC security (Checkov/KICS), container & supply-chain hardening (Trivy, Cosign), runtime detection with Falco, and DefectDojo vuln management.
Helps you continuously monitor and fix common security vulnerabilities in your Django application.
Cross-platform developer workstation control plane powered by chezmoi — adaptive terminal themes, AI CLI workflows, read-only MCP, WASM attestations, encrypted secrets, and SLSA-verified releases.
A collection of technical and sales resources related to Prisma Cloud Compute and Prisma Cloud Enterprise created for the PANW Channel Partner Ecosystem and other engineers working with the solution
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about DevSecOps in Cybersecurity.
AI-powered security assessment SKILLS for your codebase. Multi-language (JS, Go, Python, Rust, Java, PHP, Ruby, C#). Works with Claude Code, Codex, OpenCode, etc.
Use @xonsh wherever you go through the SSH without installation on the host.
Git Anti-Virus Scan Action - Detect trojans, viruses, malware & other malicious threats.
OWASP EKS Goat is a deliberately vulnerable EKS cluster environment to explore AWS cloud-native security through hands-on attack and defense labs with walkthrough.
This repo includes a demo that shows how a Kubernetes cluster can be hijacked and how to prevent it using common best practices.
A hands-on lab toolkit for container security, from CIS-benchmark fundamentals to architectural trust governance. 12 production-grade labs covering image hardening, signing, supply chain attestation, admission control, and runtime debugging. Designed around reproducible, production-oriented container security scenarios.
Collection of roadmaps, tools, best practice, resources about DevSecOps
All that is required to run MobSF in the ci