Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
-
Updated
Jun 2, 2026
Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
Training and certifications related to secure software development
Supply-chain security tool that cross-references your private package inventory against public registries, flags dependency confusion risks, and explains why each collision matters
Automating Windows Server Lifecycle with Jira Service Management & Assets.
Ready-to-use Claude Code configuration for Dev and Ops work: global rules, 23 skills, hooks and memory scaffolding. Generic, no personal data, one script to install.
Application Python qui récupère ses credentials PostgreSQL depuis HashiCorp Vault via AppRole, sans jamais les écrire sur disque.
IaC blast radius analyzer for Terraform and Kubernetes. Parses HCL/YAML, builds a NetworkX dependency graph, detects CIS benchmark violations via local RAG, performs multi-hop chain reasoning to discover attack paths, generates LLM attack narratives, and ranks fixes by impact.
Plataforma de DevSecOps, Software Quality e AI Trust capaz de avaliar aplicações e sistemas de IA, consolidando evidências técnicas e produzindo um Trust Score e uma certificação interna de confiança por versão do software. A plataforma consolida, não substitui, os relatórios das ferramentas (SonarQube, Trivy, Bandit, pytest, OWASP, RAGAS etc.)
A gated CI/CD security pipeline built around OWASP crAPI (an intentionally vulnerable API), paired with hands-on manual vulnerability research against the same target
End-to-end CI/CD pipeline with DevSecOps — Flask API, Docker, Trivy scan, SonarQube SAST, and AKS deployment using Azure DevOps & GitHub Actions
To associate your repository with the devesecops topic, visit your repo's landing page and select "manage topics."