Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
-
Updated
Jun 2, 2026
Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
Training and certifications related to secure software development
Ready-to-use Claude Code configuration for Dev and Ops work: global rules, 29 skills, hooks and memory scaffolding. Generic, no personal data, one script to install.
Automating Windows Server Lifecycle with Jira Service Management & Assets.
Supply-chain security tool that cross-references your private package inventory against public registries, flags dependency confusion risks, and explains why each collision matters
Plataforma de DevSecOps, Software Quality e AI Trust capaz de avaliar aplicações e sistemas de IA, consolidando evidências técnicas e produzindo um Trust Score e uma certificação interna de confiança por versão do software. A plataforma consolida, não substitui, os relatórios das ferramentas (SonarQube, Trivy, Bandit, pytest, OWASP, RAGAS etc.)
IaC blast radius analyzer for Terraform and Kubernetes. Parses HCL/YAML, builds a NetworkX dependency graph, detects CIS benchmark violations via local RAG, performs multi-hop chain reasoning to discover attack paths, generates LLM attack narratives, and ranks fixes by impact.
A Claude Code skill that analyzes your codebase and generates an evidence-based Threat Modeling Report using STRIDE, DREAD, MITRE ATT&CK and attack trees. Full mode builds a baseline report with file/line citations and Mermaid diagrams; Patch mode reviews security-relevant changes in a git time range and merges them back.
A Python tool that scans AWS accounts for common security misconfigurations, starting with publicly exposed S3 buckets.
Application Python qui récupère ses credentials PostgreSQL depuis HashiCorp Vault via AppRole, sans jamais les écrire sur disque.
End-to-end CI/CD pipeline with DevSecOps — Flask API, Docker, Trivy scan, SonarQube SAST, and AKS deployment using Azure DevOps & GitHub Actions
A gated CI/CD security pipeline built around OWASP crAPI (an intentionally vulnerable API), paired with hands-on manual vulnerability research against the same target
To associate your repository with the devesecops topic, visit your repo's landing page and select "manage topics."