Open source devsecops projects
Every project in the registry tagged devsecops, ranked by real GitHub adoption.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabi
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Find secrets with Gitleaks 🔑
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment fra
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Secure and streamline database changes with CI/CD automation
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-se
Fast, flexible VPN replacement with zero-trust security
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
Tfsec is now part of Trivy
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
Open Source Vulnerability Management Platform
Open Source Cloud Native Application Protection Platform (CNAPP)
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS b
nodejsscan is a static security code scanner for Node.js applications.
🧵 CLI tool for directly patching container images!
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. B
A security scanner for your LLM agentic workflows
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance throu
A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features com
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API
Agile Threat Modeling Toolkit
Secure secret management with public key encryption
Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software suppl
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
Related tags
Frequently asked questions
How many open source devsecops projects are there?
This registry tracks 28 projects tagged devsecops, with 239,986 GitHub stars between them. The most-adopted is shannon at 48,105 stars.
Are these devsecops projects free to use?
Yes — 27 of the 28 carry an explicit open-source licence across 5 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which devsecops project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these devsecops projects still maintained?
20 of the 28 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.