Projects with this topic
-
Toolchain image for the Coroboros security gates.
UpdatedUpdated -
-
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
DevSecOps health check for GitLab Self-Managed instances.
Updated -
Deterministic, format-preserving dependency remediation for GitLab CI — Maven first. A hundred eyes on your dependency graph.
Updated -
The evidence line and the published CI/CD Catalog. Governed, reusable pipeline components every workload builds from.
Updated -
Landing page for the Evidence Factory group. Start here for the guided walk through the six projects.
Updated -
The driver. One tool that provisions the group, applies the NIST 800-53 framework, pushes control evidence, and exports OSCAL artifacts.
Updated -
Skaledheim (SKM) is a modular platform designed to orchestrate distributed services inside a cohesive DevSecOps cluster oriented ecosystem.
Updated -
The policy plane. Pipeline Execution Policy, security policies, and external compliance controls that assess and gate every consumer.
Updated -
Consumer workload: a reusable CI/CD Catalog component. Adoption phase enforce, so an off-catalog include is blocked.
Updated -
Consumer workload: a container image. Adoption phase cutover, so the regulatory baseline blocks an unsigned image.
Updated -
Consumer workload: a Go binary. Adoption phase report, so conformance runs advisory and merge requests stay green.
Updated -
Probably the most modern and sophisticated insecure web application!
Clone of OWASP Juice Shop with GitLab branding and more.
Learn more by seeing our DevSecOps Tutorial
Updated -
Medium-interaction SSH/Telnet honeypot built with Cowrie, Loki, Promtail, and Grafana - provisioned on DigitalOcean via Terraform with a GitLab CI validation pipeline.
Updated -
Cheatsheet / IT toolbox
Updated -
AI-powered security orchestration for GitLab CI/CD. Automated vulnerability patching, threat modeling, and compliance scoring with GPT-4 and Claude AI agents.
Updated -
Static security scanner for MCP and AI-agent configurations ? secrets, excessive permissions, unsafe shells and supply-chain risk.
Updated -
D3FENDer is a security assessment and gap detection tool developed by Michael Favvas for his thesis titled "Development of a security assessment and gap detection system using the MITRE ATT&CK and D3FEND Frameworks". It uses a rule based system to grade an organization's defenses based on the input. It then detects possible gaps and suggests mitigations based on the MITRE ATT&CK and D3FEND Knowledge Bases. The tool can be used in SOC work flows.
Updated