← Back to Awesome

Sections

DevSecOps

GitHub repository ↗ synced 2026/8/9

Awesome

Curating the best DevSecOps resources and tooling.

DevSecOps is an extension of the DevOps movement that aims to bring security practices into the development lifecycle through developer-centric security tooling and processes.

Contributions welcome. Add links through pull requests or create an issue to start a discussion.

Resources

Articles

Our Approach to Employee Security Training

_Pager Duty_ - Guidelines to running security training within an organisation.

DevSecOps: Making Security Central To Your DevOps Pipeline

_Spacelift_ - An article explains what DevSecOps aims to achieve, why it’s advantageous, and how the DevSecOps lifecycle looks.

Books

Alice and Bob Learn Application Security

_Tanya Janca_ - An accessible and thorough resource for anyone seeking to incorporate, from the beginning of the System Development Life Cycle, best security practices in software development.

Communities

DevSecCon

_Snyk_ - A community that runs conferences, a blog, a podcast and a Discord dedicated to DevSecOps.

TAG Security

_Cloud Native Computing Foundation_ - TAG Security facilitates collaboration to discover and produce resources that enable secure access, policy control, and safety for operators, administrators, developers, and end-users across the cloud native ecosystem.

Conferences

AppSec Day

_OWASP_ - An Australian application security conference run by OWASP.

DevSecCon

_Snyk_ - A network of DevSecOps conferences run by Snyk.

Newsletters

Shift Security Left

_Cossack Labs_ - A free biweekly newsletter for security-aware developers covering application security, secure architecture, DevSecOps, cryptography, incidents, etc. that can be useful for builders and (to a lesser extent) for breakers.

Podcasts

Absolute AppSec

_Seth Law & Ken Johnson_ - Discussions about current events and specific topics related to application security.

Application Security Podcast

_Security Journey_ - Interviews with industry experts about specific application security concepts.

BeerSecOps

_Aqua Security_ - Breaking down the silos of Dev, Sec and Ops, discussing topics that span these subject areas.

DevSecOps Podcast Series

_OWASP_ - Discussions with thought leaders and practitioners to integrate security into the development lifecycle.

The Secure Developer

_Snyk_ - Discussion about security tools and best practices for software developers.

Secure Development Guidelines

Application Security Verification Standard

_OWASP_ - A framework of security requirements and controls to help developers design and develop secure web applications.

Coding Standards

_CERT_ - A collection of secure development standards for C, C++, Java and Android development.

Fundamental Practices for Secure Software Development

_SAFECode_ - Guidelines for implementing key secure development practices throughout the SDLC.

Proactive Controls

_OWASP_ - OWASP's list of top ten controls that should be implemented in every software development project.

Secure Coding Guidelines

_Mozilla_ - A guideline containing specific secure development standards for secure web application development.

Secure Coding Practices Quick Reference Guide

_OWASP_ - A checklist to verify that secure development standards have been followed.

Secure Development Lifecycle Framework

Building Security In Maturity Model (BSIMM)

_Synopsys_ - A framework for software security created by observing and analysing data from leading software security initiatives.

Secure Development Lifecycle

_Microsoft_ - A collection of tools and practices that serve as a framework for the secure development lifecycle.

Secure Software Development Framework

_NIST_ - A framework consisting of practices, tasks and implementation examples for a secure development lifecycle.

Software Assurance Maturity Model

_OWASP_ - A framework to measure and improve the maturity of the secure development lifecycle.

Toolchains

Cloud Security and DevSecOps Best Practices _and_ Securing Web Application Technologies (SWAT) Checklist

_SANS_ - A poster containing the Securing Web Application Technologies (SWAT) Checklist, SANS Cloud Security Curriculum, Cloud Security Top 10, Top 12 Kubernetes Threats, and Secure DevOps Toolchain.

Periodic Table of DevOps Tools

_XebiaLabs_ - A collection of DevSecOps tooling categorised by tool functionality.

Training

Application Security Education

_Duo Security_ - Training materials created by the Duo application security team, including introductory and advanced training presentations and hands-on labs.

Cybrary

_Cybrary_ - Subscription based online courses with dedicated categories for cybersecurity and DevSecOps.

PentesterLab

_PentesterLab_ - Hands on labs to understand and exploit simple and advanced web vulnerabilities.

Practical DevSecOps

_Practical DevSecOps_ - Learn DevSecOps concepts, tools, and techniques from industry experts with practical DevSecOps using state of the art browser-based labs.

SafeStack

_SafeStack_ - Security training for software development teams, designed to be accessible to individuals and small teams as well as larger organisations.

Secure Code Warrior

_Secure Code Warrior_ - Gamified and hands-on secure development training with support for courses, assessments and tournaments.

SecureFlag

_OWASP_ - Hands-on secure coding training for Developers and Build/Release Engineers.

Security Training for Engineers

_Pager Duty_ - A presentation created and open-sourced by PagerDuty to provide security training to software engineers.

Security Training for Everyone

_Pager Duty_ - A presentation created and open-sourced by PagerDuty to provide security training employees.

Semgrep Academy

_Semgrep_ - Free, on-demand courses covering topics including API security, secure coding and application security.

Web Security Academy

_PortSwigger_ - A set of materials and labs to learn and exploit common web vulnerabilities.

WeHackPuple

_WeHackPurple_ - Online courses that teach application security theory and hands-on technical lessons.

Wikis

DevSecOps Hub

_Snyk_ - Introduction to key DevSecOps concepts, processes and technologies.

SecureFlag Knowledge Base

_OWASP_ - A repository of information about software vulnerabilities and how to prevent them.

Tools

Dependency Management

Deepfence ThreatMapper

Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.

Dependabot

_GitHub_ - Automatically scan GitHub repositories for vulnerabilities and create pull requests to merge in patched dependencies.

Dependency-Check

_OWASP_ - Scans dependencies for publicly disclosed vulnerabilities using CLI or build server plugins.

Dependency-Track

_OWASP_ - Monitor the volume and severity of vulnerable dependencies across multiple projects over time.

JFrog XRay

_JFrog_ - Security and compliance analysis for artifacts stored in JFrog Artifactory.

NPM Audit

_NPM_ - Vulnerable package auditing for node packages built into the npm CLI.

Renovate

_WhiteSource_ - Automatically monitor and update software dependencies for multiple frameworks and languages using a CLI or git repository apps.

Requires.io

_Olivier Mansion & Alexis Tabary_ - Automated vulnerable dependency monitoring and upgrades for Python projects.

Snyk Open Source

_Snyk_ - Automated vulnerable dependency monitoring and upgrades using Snyk's dedicated vulnerability database.

Open source software packages can speed up the development process by allowing developers to implement functionality without having to write all of the code. However, with the open source code comes open source vulnerabilities. Dependency management tools help manage vulnerabilities in open source packages by identifying and updating packages with known vulnerabilities.

Dynamic Analysis

Automatic API Attack Tool

_Imperva_ - Perform automated security scanning against an API based on an API specification.

BurpSuite Enterprise Edition

_PortSwigger_ - BurpSuite's web application vulnerability scanner used widely by penetration testers, modified with CI/CD integration and continuous monitoring over multiple web applications.

Gauntlt

_Gauntlt_ - A Behaviour Driven Development framework to run security scans using common security tools and test output, defined using Gherkin syntax.

Netz

_Spectral_ - Discover internet-wide misconfigurations, using zgrab2 and others.

RESTler

_Microsoft_ - A stateful RESTful API scanner based on peer-reviewed research papers.

SSL Labs Scan

_SSL Labs_ - Automated scanning for SSL / TLS configuration issues.

Zed Attack Proxy (ZAP)

_OWASP_ - An open-source web application vulnerability scanner, including an API for CI/CD integration.

Dynamic Analysis Security Testing (DAST) is a form of black-box security testing where a security scanner interacts with a running instance of an application, emulating malicious activity to find common vulnerabilities. DAST tools are commonly used in the initial phases of a penetration test, and can find vulnerabilities such as cross-site scripting, SQL injection, cross-site request forgery and information disclosure.

Infrastructure as Code Analysis

Checkov

_Bridgecrew_ - Scan Terraform, AWS CloudFormation and Kubernetes templates for insecure configuration.

KICS

_Checkmarx_ - Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle.

Spectral DeepConfig

_Spectral_ - Find misconfiguration both in infrastructure as well as apps as early as commit time.

Terrascan

_Accurics_ - Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Cfn Nag

_Stelligent_ - Scan AWS CloudFormation templates for insecure configuration.

Clair

_Red Hat_ - Scan App Container and Docker containers for publicly disclosed vulnerabilities.

Dagda

_Elías Grande_ - Compares OS and software dependency versions installed in Docker containers with public vulnerability databases, and also performs virus scanning.

Docker-Bench-Security

_Docker_ - The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

Grype

_Anchore_ - An easy-to-integrate open source vulnerability scanning tool for container images and filesystems.

Hadolint

_Hadolint_ - Checks a Dockerfile against known rules and validates inline bash code in RUN statements.

Snyk Container

_Snyk_ - Scan Docker and Kubernetes applications for security vulnerabilities during CI/CD or via continuous monitoring.

Trivy

_Aqua Security_ - Simple and comprehensive vulnerability scanner for containers.

Regula

_Fugue_ - Evaluate Terraform infrastructure-as-code for potential security misconfigurations and compliance violations prior to deployment.

Terraform Compliance

_terraform-compliance_ - A lightweight, security and compliance focused test framework against terraform to enable negative testing capability for your infrastructure-as-code.

Tfsec

_Liam Galvin_ - Scan Terraform templates for security misconfiguration and noncompliance with AWS, Azure and GCP security best practice.

Kubescape

_Cloud Native Computing Foundation_ - An open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters.

Kube-Score

_Gustav Westling_ - Scan Kubernetes object definitions for security and performance misconfiguration.

Kubectrl Kubesec

_ControlPlane_ - Plugin for kubesec.io to perform security risk analysis for Kubernetes resources.

Ansible-Lint

_Ansible Community_ - Checks playbooks for practices and behaviour that could potentially be improved. As a community backed project ansible-lint supports only the last two major versions of Ansible.

Infrastructure as Code allows applications to be deployed reliably to a consistent environment. This not only ensures that infrastructure is consistently hardened, but also provides an opportunity to statically and dynamically analyse infrastructure definitions for vulnerable dependencies, hard-coded secrets, insecure configuration and unintentional changes in security configuration. The following tools facilitate this analysis.

Multi-Platform

Cloud Formation

Containers

Terraform

Kubernetes

Ansible

Intentionally Vulnerable Applications

Bad SSL

_The Chromium Project_ - A container running a number of webservers with poor SSL / TLS configuration. Useful for testing tooling.

Cfngoat

_Bridgecrew_ - Cloud Formation templates for creating stacks of intentionally insecure services in AWS. Ideal for testing the Cloud Formation Infrastructure as Code Analysis tools above.

CI/CD Goat

_Cider Security_ - A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Damn Vulnerable Web App

_Ryan Dewhurst_ - A web application that provides a safe environment to understand and exploit common web vulnerabilities.

Juice Shop

_OWASP_ - A web application containing the OWASP Top 10 security vulnerabilities and more.

Kubernetes Goat

_Madhu Akula_ - Intentionally vulnerable cluster environment to learn and practice Kubernetes security.

NodeGoat

_OWASP_ - A Node.js web application that demonstrates and provides ways to address common security vulnerabilities.

Pentest-Ground

_Pentest-Tools.com_ - Pentest-Ground is a free playground with deliberately vulnerable web applications and network services.

Terragoat

_Bridgecrew_ - Terraform templates for creating stacks of intentionally insecure services in AWS, Azure and GCP. Ideal for testing the Terraform Infrastructure as Code Analysis tools above.

Vulnerable Web Apps Directory

_OWASP_ - A collection of vulnerable web applications for learning purposes.

WrongSecrets

_OWASP_ - Vulnerable app with examples showing how to not use secrets

Intentionally vulnerable applications are often useful when developing security tests and tooling to provide a place you can run tests and make sure they fail correctly. These applications can also be useful for understanding how common vulnerabilities are introduced into applications and let you practice your skills at exploiting them.

Monitoring

Csper

_Csper_ - A set of Content Security Policy tools that can test policies, monitor CSP reports and provide metrics and alerts.

Streamdal

_Streamdal_ - Embed privacy controls in your application code to detect and monitor PII as it enters and leaves your systems, preventing it from reaching unintended databases, data streams, or pipelines.

It's not enough to test and harden our software in the lead up to a release. We must also monitor our production software for usage, performance and errors to capture malicious behavior and potential security flaws that we may need to respond to or address. A wide variety of tools are available to monitor different aspects of production software and infrastructure.

Secrets Management

Ansible Vault

_Ansible_ - Securely store secrets within Ansible pipelines.

AWS Key Management Service (KMS)

_Amazon AWS_ - Create and manage cryptographic keys in AWS.

AWS Secrets Manager

_Amazon AWS_ - Securely store retrievable application secrets in AWS.

Azure Key Vault

_Microsoft Azure_ - Securely store secrets within Azure.

BlackBox

_StackExchange_ - Encrypt credentials within your code repository.

Chef Vault

_Chef_ - Securely store secrets within Chef.

CredStash

_Fugue_ - Securely store secrets within AWS using KMS and DynamoDB.

CyberArk Application Access Manager

_CyberArk_ - Secrets management for applications including secret rotation and auditing.

Docker Secrets

_Docker_ - Store and manage access to secrets within a Docker swarm.

Git Secrets

_Amazon AWS_ - Scan git repositories for secrets committed within code or commit messages.

Gopass

_Gopass_ - Password manager for teams relying on Git and gpg. Manages secrets in encrypted files and repositories.

Google Cloud Key Management Service (KMS)

_Google Cloud Platform_ - Securely store secrets within GCP.

HashiCorp Vault

_HashiCorp_ - Securely store secrets via UI, CLI or HTTP API.

Keyscope

_Spectral_ - Keyscope is an open source key and secret workflow tool (validation, invalidation, etc.) built in Rust.

Pinterest Knox

_Pinterest_ - Securely store, rotate and audit secrets.

Secrets Operations (SOPS)

_Mozilla_ - Encrypt keys stored within YAML, JSON, ENV, INI and BINARY files.

Teller

_Spectral_ - A secrets management tool for developers - never leave your command line for secrets.

The software we write needs to use secrets (passwords, API keys, certificates, database connection strings) to access resources, yet we cannot store secrets within the codebase as this leaves them vulnerable to compromise. Secret management tools provide a means to securely store, access and manage secrets.

Secrets Scanning

CredScan

_Microsoft_ - A credential scanning tool that can be run as a task in Azure DevOps pipelines.

Detect Secrets

_Yelp_ - An aptly named module for (surprise, surprise) detecting secrets within a code base.

GitGuardian

_GitGuardian_ - A web-based solution that scans and monitors public and private git repositories for secrets.

Gitleaks

_Zachary Rice_ - Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repositories.

git-secrets

_AWS Labs_ - Scans commits, commit messages and merges for secrets. Native support for AWS secret patterns, but can be configured to support other patterns.

Nightfall

_Nightfall_ - A web-based platform that monitors for sensitive data disclosure across several SDLC tools, including GitHub repositories.

Repo-supervisor

_Auth0_ - Secrets scanning tool that can run as a CLI, as a Docker container or in AWS Lambda.

SpectralOps

_Spectral_ - Automated code security, secrets, tokens and sensitive data scanning.

truffleHog

_Truffle Security_ - Searches through git repositories for secrets, digging deep into commit history and branches.

Source control is not a secure place to store secrets such as credentials, API keys or tokens, even if the repo is private. Secrets scanning tools can scan and monitor git repositories and pull-requests for secrets, and can be used to prevent secrets from being committed, or to find and remove secrets that have already been committed to source control.

Static Analysis

DevSkim

_Microsoft_ - A set of IDE plugins, CLIs and other tools that provide security analysis for a number of programming languages.

Graudit

_Eldar Marcussen_ - Grep source code for potential security flaws with custom or pre-configured regex signatures.

Hawkeye

_Hawkeyesec_ - Modularised CLI tool for project security, vulnerability and general risk highlighting.

LGTM

_Semmle_ - Scan and monitor code for security vulnerabilities using custom or built-in CodeQL queries.

RIPS

_RIPS Technologies_ - Automated static analysis for PHP, Java and Node.js projects.

SemGrep

_r2c_ - Semgrep is a fast, open-source, static analysis tool that finds bugs and enforces code standards at editor, commit, and CI time.

SonarLint

_SonarSource_ - An IDE plugin that highlights potential security security issues, code quality issues and bugs.

SonarQube

_SonarSource_ - Scan code for security and quality issues with support for a wide variety of languages.

FlawFinder

_David Wheeler_ - Scan C / C++ code for potential security weaknesses.

Puma Scan

_Puma Security_ - A Visual Studio plugin to scan .NET projects for potential security flaws.

Conftest

_Instrumenta_ - Create custom tests to scan any configuration file for security flaws.

Selefra

_Selefra_ - An open-source policy-as-code software that provides analytics for multi-cloud and SaaS.

Deep Dive

_Discotek.ca_ - Static analysis for JVM deployment units including Ear, War, Jar and APK.

Find Security Bugs

_OWASP_ - SpotBugs plugin for security audits of Java web applications. Supports Eclipse, IntelliJ, Android Studio and SonarQube.

SpotBugs

_SpotBugs_ - Static code analysis for Java applications.

ESLint

_JS Foundation_ - Linting tool for JavaScript with multiple security linting rules available.

Golang Security Checker

_securego_ - CLI tool to scan Go code for potential security flaws.

Security Code Scan

_Security Code Scan_ - Static code analysis for C# and VB.NET applications.

Phan

_Phan_ - Broad static analysis for PHP applications with some support for security scanning features.

PHPCS Security Audit

_Floe_ - PHP static analysis with rules for PHP, Drupal 7 and PHP related CVEs.

Progpilot

_Design Security_ - Static analysis for PHP source code.

Bandit

_Python Code Quality Authority_ - Find common security vulnerabilities in Python code.

Brakeman

_Justin Collins_ - Static analysis tool which checks Ruby on Rails applications for security vulnerabilities.

DawnScanner

_Paolo Perego_ - Security scanning for Ruby scripts and web application. Supports Ruby on Rails, Sinatra and Padrino frameworks.

Static Analysis Security Testing (SAST) tools scan software for vulnerabilities without executing the target software. Typically, static analysis will scan the source code for security flaws such as the use of unsafe functions, hard-coded secrets and configuration issues. SAST tools often come in the form of IDE plugins and CLIs that can be integrated into CI/CD pipelines.

Multi-Language Support

C / C++

C#

Configuration Files

Java

JavaScript

Go

.NET

PHP

Python

Ruby

Supply Chain Security

Harden Runner GitHub Action

_StepSecurity_ - installs a security agent on the GitHub-hosted runner (Ubuntu VM) to prevent exfiltration of credentials, detect compromised dependencies and build tools, and detect tampering of source code during the build.

Overlay

_SCAR_ - a browser extension helping developers evaluate open source packages before picking them.

Preflight

_Spectral_ - helps you verify scripts and executables to mitigate supply chain attacks in your CI and other systems, such as in the recent [Codecov hack](https://spectralops.io/blog/credentials-risk-supply-chain-lessons-from-the-codecov-breach/).

Sigstore

sigstore is a set of free to use and open source tools, including [fulcio](https://github.com/sigstore/fulcio), [cosign](https://github.com/sigstore/cosign) and [rekor](https://github.com/sigstore/rekor), handling digital signing, verification and checks for provenance needed to make it safer to distribute and use open source software.

Syft

_Anchore_ - A CLI tool for generating a Software Bill of Materials (SBOM) from container images and filesystems.

Supply chain attacks come in different forms, targeting parts of the SDLC that are inherently 3rd party: tools in CI, external code that's been executed, and more. Supply chain security tooling can defend against these kinds of attacks.

Threat Modelling

Awesome Threat Modelling

_Practical DevSecOps_ - A curated list of threat modelling resources.

SecuriCAD

_Forseeti_ - Treat modelling and attack simulations for IT infrastructure.

IriusRisk

_IriusRisk_ - Draw threat models and capture threats and countermeasures and manage risk.

Raindance Project

_DevSecOps_ - Use attack maps to identify attack surface and adversary strategies that may lead to compromise.

SD Elements

_Security Compass_ - Identify and rank threats, generate actionable tasks and track related tickets.

Threat Dragon

_OWASP_ - Threat model diagramming tool.

Threat Modelling Tool

_Microsoft_ - Threat model diagramming tool.

Threatspec

_Threatspec_ - Define threat modelling as code.

Threat modelling is an engineering exercise that aims to identify threats, vulnerabilities and attack vectors that represent a risk to something of value. Based on this understanding of threats, we can design, implement and validate security controls to mitigate threats. The following list of tools assist the threat modelling process.

Related Lists

Awesome Dynamic Analysis

_Matthias Endler_ - A collection of dynamic analysis tools and code quality checkers.

Awesome Platform Engineering

A curated list of solutions, tools and resources for _Platform Engineering_

Awesome Static Analysis

_Matthias Endler_ - A collection of static analysis tools and code quality checkers.

Awesome Threat Modelling

_Practical DevSecOps_ - A curated list of threat modeling resources.

Vulnerable Web Apps Directory

_OWASP_ - A collection of vulnerable web applications for learning purposes.