Open source devsecops projects

Every project in the registry tagged devsecops, ranked by real GitHub adoption.

projects 28 combined stars ★ 240K refresh nightly
01 shannon ★ 48K

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabi

last push9 days ago languageTypeScript licenseAGPL-3.0
02 trivy ★ 38K

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

last push8 hours ago languageGo licenseApache-2.0
03 gitleaks ★ 29K

Find secrets with Gitleaks 🔑

last push9 days ago languageGo licenseMIT
04 Mobile-Security-Framework-MobSF ★ 22K

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment fra

last push9 days ago languageJavaScript licenseGPL-3.0
05 prowler ★ 15K

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

last push7 hours ago languagePython licenseApache-2.0
06 Bytebase ★ 14K

Secure and streamline database changes with CI/CD automation

last push3 hours ago languageGo license
07 codex-security ★ 11K

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-se

last push4 hours ago languageTypeScript licenseApache-2.0
08 FireZone ★ 9.1K

Fast, flexible VPN replacement with zero-trust security

last push18 hours ago languageElixir licenseApache-2.0
09 steampipe ★ 8.0K

Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.

last push11 hours ago languageGo licenseAGPL-3.0
10 tfsec ★ 7.0K

Tfsec is now part of Trivy

last push6 months ago languageGo licenseMIT
11 DeepAudit ★ 7.0K

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

last push38 hours ago languagePython licenseAGPL-3.0
12 faraday ★ 6.7K

Open Source Vulnerability Management Platform

last push13 days ago languagePython licenseGPL-3.0
13 ThreatMapper ★ 5.3K

Open Source Cloud Native Application Protection Platform (CNAPP)

last push4 months ago languageTypeScript licenseApache-2.0
14 kics ★ 2.7K

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS b

last push12 hours ago languageOpen Policy Agent licenseApache-2.0
15 nodejsscan ★ 2.6K

nodejsscan is a static security code scanner for Node.js applications.

last push11 months ago languageCSS licenseGPL-3.0
16 copacetic ★ 1.7K

🧵 CLI tool for directly patching container images!

last push2 days ago languageGo licenseApache-2.0
17 pentest-ai ★ 1.7K

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

last push5 days ago languagePython licenseMIT
18 mantis ★ 1.6K

A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.

last push5 days ago languagePython licenseApache-2.0
19 YaraHunter ★ 1.3K

🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍

last push6 months ago languageGo licenseApache-2.0
20 dep-scan ★ 1.3K

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. B

last push1 months ago languagePython licenseMIT
21 agentic-radar ★ 1.1K

A security scanner for your LLM agentic workflows

last push10 months ago languagePython licenseApache-2.0
22 reconmap ★ 981

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance throu

last push4 days ago languageJavaScript licenseApache-2.0
23 vuln-bank ★ 933

A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features com

last push6 days ago languageHTML licenseMIT
24 ship-safe ★ 844

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API

last pushyesterday languageJavaScript licenseMIT
25 threagile ★ 780

Agile Threat Modeling Toolkit

last push5 months ago languageGo licenseMIT
26 Keyshade ★ 768

Secure secret management with public key encryption

last push5 months ago languageTypeScript licenseMPL-2.0
27 packj ★ 693

Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software suppl

last push16 hours ago languagePython licenseAGPL-3.0
28 bomber ★ 624

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

last push7 months ago languageGo licenseMPL-2.0

Related tags

← all tags

Frequently asked questions

How many open source devsecops projects are there?

This registry tracks 28 projects tagged devsecops, with 239,986 GitHub stars between them. The most-adopted is shannon at 48,105 stars.

Are these devsecops projects free to use?

Yes — 27 of the 28 carry an explicit open-source licence across 5 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which devsecops project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these devsecops projects still maintained?

20 of the 28 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.