gopass by gopasspw

The slightly more awesome standard unix password manager for teams

created at Feb. 2, 2017, 12:33 p.m.

Go

79 +0

5,681 +6

475 +0

GitHub
scanner-cli by hawkeyesec

A project security/vulnerability/risk scanning tool

created at March 18, 2017, 3:24 p.m.

JavaScript

19 +0

359 +0

89 +0

GitHub
regula by fugue

Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes security and compliance using Open Policy Agent/Rego

created at Dec. 17, 2019, 2:27 p.m.

Open Policy Agent

30 +0

936 +2

106 +0

GitHub
kics by Checkmarx

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

created at July 8, 2020, 9:46 p.m.

Open Policy Agent

25 +0

1,924 +9

286 +0

GitHub
appsec-education by duo-labs

Presentations, training modules, and other education materials from Duo Security's Application Security team.

created at Oct. 22, 2019, 4:40 p.m.

JavaScript

9 +0

67 +0

14 +0

GitHub
netz by SpectralOps

Discover internet-wide misconfigurations while drinking coffee

created at March 3, 2021, 6:47 p.m.

Go

14 +0

376 +1

46 +0

GitHub
detect-secrets by Yelp

An enterprise friendly way of detecting and preventing secrets in code.

created at Dec. 5, 2017, 12:38 a.m.

Python

48 +0

3,508 +16

436 +1

GitHub
preflight by SpectralOps

preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

created at April 29, 2021, 10:37 a.m.

Go

6 +0

150 +0

45 +0

GitHub
tfsec by aquasecurity

Security scanner for your Terraform code

created at March 4, 2019, 4:56 p.m.

Go

71 +0

6,589 +6

530 +0

GitHub
juice-shop by juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

created at Sept. 19, 2014, 2:53 p.m.

TypeScript

156 +0

9,651 +20

9,526 +49

GitHub
keyscope by SpectralOps

Keyscope is a key and secret workflow (validation, invalidation, etc.) tool built in Rust

created at Oct. 1, 2021, 12:01 p.m.

Rust

17 +0

377 +0

119 +0

GitHub
cosign by sigstore

Code signing and transparency for containers and binaries

created at Feb. 4, 2021, 12:49 p.m.

Go

51 -1

4,148 +19

497 -1

GitHub
fulcio by sigstore

Sigstore OIDC PKI

created at Feb. 23, 2021, 3:19 p.m.

Go

17 +0

610 +2

127 +1

GitHub
rekor by sigstore

Software Supply Chain Transparency Log

created at June 17, 2020, 12:04 p.m.

Go

18 +0

840 +2

156 +0

GitHub
trufflehog by trufflesecurity

Find and verify secrets

created at Dec. 31, 2016, 5:08 a.m.

Go

167 +1

14,096 +66

1,532 +4

GitHub
terrascan by tenable

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

created at Sept. 11, 2017, 3:11 a.m.

Go

68 +1

4,538 +4

495 +1

GitHub
teller by tellerops

Cloud native secrets management for developers - never leave your command line for secrets.

created at March 24, 2021, 10:49 a.m.

Rust

28 +2

2,563 +7

166 +1

GitHub
harden-runner by step-security

Network egress filtering and runtime security for GitHub-hosted and self-hosted runners

created at Oct. 28, 2021, 4:58 p.m.

TypeScript

6 -1

533 +2

41 +0

GitHub
gitleaks by gitleaks

Protect and discover secrets using Gitleaks 🔑

created at Jan. 27, 2018, 6:19 p.m.

Go

153 +1

15,400 +27

1,326 +1

GitHub
selefra by selefra

The open-source policy-as-code software that provides analysis for Multi-Cloud and SaaS environments, you can get insight with natural language (powered by OpenAI).

created at March 21, 2023, 4:28 p.m.

Go

6 +0

510 +0

36 +0

GitHub