General

Repositories

  • awesome-devsecops: Curating the best DevSecOps resources and tooling ๐ŸŒŸ (Recommended)
  • dynamic-analysis: A curated list of dynamic analysis tools and linters
  • static-analysis: A curated list of static analysis (SAST) tools and linters ๐ŸŒŸ (Recommended)
  • awesome-iam: ๐Ÿ‘ค Identity and Access Management knowledge for cloud platforms ๐ŸŒŸ (Recommended)

Technique

Technology

Stories

DevSecOps Tools

center

SAST

  • Sonarqube: An on-premise analysis tool designed to detect coding issues ๐ŸŒŸ (Recommended)
  • Sonar Rule: The collections of rule integrate into Sonarqube Server
  • trivy: Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more ๐ŸŒŸ (Recommended)
  • GitGuardian ggshield: a CLI application that runs in your local environment or in a CI environment to help you detect more than 500+ types of secrets. ๐ŸŒŸ (Recommended)