Skip to main content

Ultimate DevSecOps library

6.8k
GitHub Stars
211
Curated Resources
20
Categories
6 hours ago
Last Refreshed
Contribution rulesPre-commit time toolsSecrets managementOSS and Dependency managementSupply chain specific toolsSASTDASTIASTContinuous deployment securityKubernetesContainersMulti-CloudAWSGoogle cloud platformMicrosoft AzurePolicy as codeChaos engineeringInfrastructure as code securityNetwork Intrusion PreventionOrchestration

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me aws resources from devsecops"

Installation instructions →

What's inside

AWS

  • AirIAM

    IAM Least Privilege anmalyzer and Terraformer

  • AWS Compliance

    Check compliance of AWS configurations to security best practices.

  • AWS Firewall factory

    Deploy, update, and stage your WAFs while managing them centrally via FMS

  • aws-iam-authenticator

    A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

  • AWS Insights

    Visualize AWS inventory and permissions through relationship graphs.

  • aws-inventory

    Helps to discover all AWS resources created in an account

DAST

  • Akto

    API Security Testing with 150+ YAML Tests

  • nikto

    Nikto web server scanner

  • Nuclei

    Template based security scanning tool

  • oss-fuzz

    OSS-Fuzz: Continuous Fuzzing for Open Source Software

  • purpleteam

    CLI DAST tool incubator project

  • skipfish

    Skipfish is an active web application security reconnaissance tool

Containers

  • Anchore

    Centralized service for inspection, analysis, and certification of container images

  • Clair

    Docker vulnerability scanner

  • Copacetic

    CLI tool for directly patching container images

  • Cosign

    Container signing

  • Deepfence ThreatMapper

    Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

  • Docker bench

    Docker benchmarking against CIS

Infrastructure as code security

  • Ansible Security Scanner

    Static security scanner for Ansible playbooks, roles, and collections; outputs SARIF, CycloneDX SBOM, and GitLab SAST.

  • cfn_nag

    Looks for insecure patterns in CloudFormation

  • Checkov

    Checkov is a static code analysis tool for infrastructure-as-code

  • KICS

    Checkmarx security testing opensource for IaC

  • Sysdig IaC scanner action

    Scans your repository with Sysdig IAC Scanner and report the vulnerabilities.

  • Terraform Compliance for AWS

    Check compliance of Terraform configurations to AWS security best practices.

Secrets management

  • Ansible vault

    Encryption/decryption utility for Ansible data files

  • AWS secrets manager GH action

    AWS secrets manager docs

  • aws-vault

    AWS Vault is a tool to securely store and access AWS credentials in a development environment

  • Chef vault

    allows you to encrypt a Chef Data Bag Item

  • GitLeaks

    Gitleaks is a scanning tool for detecting hardcoded secrets

  • GitRob

    Gitrob is a tool to help find potentially sensitive files pushed to public repositories on Github

Orchestration

Chaos engineering

  • AWS FIS samples

    AWS Fault injection simulator samples

  • Chaos Engine

    The Chaos Engine is a tool that is designed to intermittently destroy or degrade application resources running in cloud based infrastructure. These events are designed to occur while the appropriate resources are available to resolve the issue if the platform fails to do so on it's own.

  • chaoskube

    Test how your system behaves under arbitrary pod failures.

  • chaos-mesh

    It is a cloud-native Chaos Engineering platform that orchestrates chaos on Kubernetes environments

  • Chaos monkey

    Chaos Monkey is responsible for randomly terminating instances in production to ensure that engineers implement their services to be resilient to instance failures.

  • CloudNuke

    CLI tool to delete all resources in an AWS account

Microsoft Azure

Showing a sample of 211 resources. View the full list on GitHub →