Skip to main content

:books: A curated list of awesome CI CD security resources

832
GitHub Stars
94
Curated Resources
8
Categories
17 hours ago
Last Refreshed
BooksGuidelinesBlogsVideosRepositoriesToolsPlaygroundCases

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me gitlab resources from awesome-cicd-security"

Installation instructions →

What's inside

Tools

  • actionlint

    A static checker for GitHub Actions workflow files.

  • Cimon

    Runtime security solution for your CI/CD pipeline.

  • Gato

    A tool that helps blue teamers and offensive security practitioners find weaknesses in GitHub organization's public and private repositories.

  • gh-hijack-runner

    A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

  • Harden-Runner

    Network egress filtering and runtime security for GitHub-hosted and self-hosted runners.

  • nord-stream

    Nord Stream is a tool that allows you extract secrets stored inside CI/CD environments by deploying malicious pipelines.

Showing a sample of 94 resources. View the full list on GitHub →