Skip to content
#

shift-left-security

Here are 34 public repositories matching this topic...

High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!

  • Updated Oct 5, 2026
  • Go

A complete DevSecOps CI/CD automation pipeline for a Node.js application using GitHub Actions, Docker, Trivy security scanning, and Kubernetes (Minikube), implementing shift-left security and cloud-native deployment practices.

  • Updated Jan 12, 2026
  • JavaScript

Advanced Conftest GitHub Action for Terraform, Kubernetes, Helm & Dockerfile policy scanning with SARIF, GitHub Security, Slack, Teams and Google Chat notifications.

  • Updated Jun 20, 2026
  • JavaScript

DevSecOps Playground: a working comparison of an insecure and secure CI/CD pipeline running the same app. The insecure pipeline ships a SQL injection and hardcoded secret straight to production; the secure pipeline catches both with Semgrep, Trivy, CodeQL, and Cosign before deploy.

  • Updated Aug 15, 2026
  • Python

End-to-end DevSecOps CI/CD pipeline integrating SAST, SCA, Secrets Scanning, Container Security, and DAST with automated security gates and deployment blocking using GitHub Actions.

  • Updated May 31, 2026
  • Python

Add this topic to your repo

To associate your repository with the shift-left-security topic, visit your repo's landing page and select "manage topics."

Learn more