High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
-
Updated
Oct 5, 2026 - Go
High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
Curated catalog of generally useful kpt functions
TrendAI Vision One Container Security Scan Action
Static analysis from configs → Kubernetes NetworkPolicies in seconds
Managing GitHub Advanced Security (GHAS) Controls at Scale
A complete DevSecOps CI/CD automation pipeline for a Node.js application using GitHub Actions, Docker, Trivy security scanning, and Kubernetes (Minikube), implementing shift-left security and cloud-native deployment practices.
Advanced Conftest GitHub Action for Terraform, Kubernetes, Helm & Dockerfile policy scanning with SARIF, GitHub Security, Slack, Teams and Google Chat notifications.
Pipeline DevSecOps experimental para TCC, medindo o impacto de SAST, SCA e DAST no lead time de CI/CD com FastAPI, Docker, Kubernetes, GitHub Actions e SonarQube.
Pre-cloud web application security assessment including vulnerability analysis, remediation, and cloud security controls.
Enterprise-style DevSecOps CI/CD pipeline demo using GitHub Actions, Semgrep, CodeQL, TruffleHog, pip-audit, and pre-commit.
Enterprise DevSecOps pipeline: GitHub Actions, Terraform, container security scanning, SAST/DAST, policy-as-code, and automated compliance validation
Catch IaC security misconfigurations before production. 100+ rules across Terraform, CloudFormation & Ansible. 9 compliance frameworks.
Servidor LSP para análise estática e conformidade contínua com a LGPD em pipelines DevSecOps (Compliance as Code).
A Java DevSecOps CI/CD pipeline integrating SonarCloud, Snyk and Trivy to evaluate shift-left security, vulnerability detection and delivery trade-offs.
DevSecOps Playground: a working comparison of an insecure and secure CI/CD pipeline running the same app. The insecure pipeline ships a SQL injection and hardcoded secret straight to production; the secure pipeline catches both with Semgrep, Trivy, CodeQL, and Cosign before deploy.
End-to-end DevSecOps CI/CD pipeline integrating SAST, SCA, Secrets Scanning, Container Security, and DAST with automated security gates and deployment blocking using GitHub Actions.
Enterprise security-focused CI/CD pipeline integrating source validation, Terraform plan/apply workflows, approval gates, container deployments, and automated rollback controls.
Git hooks for improving developer experience and security
Beyond Shift Left: Runtime Security with Falco on AWS EKS
CI/CD compliance gate for Australian ISM and Essential Eight — checks K8s, Docker, and IaC via OPA/Rego policies
To associate your repository with the shift-left-security topic, visit your repo's landing page and select "manage topics."