Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
-
Updated
Jun 2, 2026
Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
Training and certifications related to secure software development
Ready-to-use Claude Code configuration for Dev and Ops work: global rules, 29 skills, hooks and memory scaffolding. Generic, no personal data, one script to install.
Automating Windows Server Lifecycle with Jira Service Management & Assets.
Supply-chain security tool that cross-references your private package inventory against public registries, flags dependency confusion risks, and explains why each collision matters
IaC blast radius analyzer for Terraform and Kubernetes. Parses HCL/YAML, builds a NetworkX dependency graph, detects CIS benchmark violations via local RAG, performs multi-hop chain reasoning to discover attack paths, generates LLM attack narratives, and ranks fixes by impact.
Plataforma de DevSecOps, Software Quality e AI Trust capaz de avaliar aplicações e sistemas de IA, consolidando evidências técnicas e produzindo um Trust Score e uma certificação interna de confiança por versão do software. A plataforma consolida, não substitui, os relatórios das ferramentas (SonarQube, Trivy, Bandit, pytest, OWASP, RAGAS etc.)
A Python tool that scans AWS accounts for common security misconfigurations, starting with publicly exposed S3 buckets.
A Claude Code skill that analyzes your codebase and generates an evidence-based Threat Modeling Report using STRIDE, DREAD, MITRE ATT&CK and attack trees. Full mode builds a baseline report with file/line citations and Mermaid diagrams; Patch mode reviews security-relevant changes in a git time range and merges them back.
Application Python qui récupère ses credentials PostgreSQL depuis HashiCorp Vault via AppRole, sans jamais les écrire sur disque.
A gated CI/CD security pipeline built around OWASP crAPI (an intentionally vulnerable API), paired with hands-on manual vulnerability research against the same target
End-to-end CI/CD pipeline with DevSecOps — Flask API, Docker, Trivy scan, SonarQube SAST, and AKS deployment using Azure DevOps & GitHub Actions
To associate your repository with the devesecops topic, visit your repo's landing page and select "manage topics."