Curating the best DevSecOps resources and tooling.
-
Updated
Aug 2, 2024
Curating the best DevSecOps resources and tooling.
A multi-vault secret injection tool for safely injecting secrets into app environment
A controlled environment for demonstrating and understanding buffer overflow vulnerabilities in web applications. This project is designed for educational purposes as part of secure software development training.
Excalidraw library for threat modeling diagrams
DocF-Sec-Check helps to make your Dockerfile commands more secure.
Vulnerable React/Next application
🛡 Scan GitHub repositories for dependency vulnerabilities using OSV database. Supports npm, PyPI, RubyGems, Go, and PHP.
DSL Core - Specification for Audit-by-Design - Human & machine-readable domain-specific language (DSL) for defining, validating, and auditing software requirements. Open specification, free to use and extend.
The place where you will find all security related topics/tools/techniques made by developers for developers concerned about security.
Fixing an Insecure Blog Application.
A program that checks and removes unwanted input ensuring that data conforms to security-related requirements.
Secure software process project focused on software security analysis and practices.
A security platform that watches, protects, and scales your microservices.
This project includes a Node.js backend service that provides APIs related to file storage, note storage, and authentication features. The main target of this application is to securely store data in storage. The project utilizes some secure software development methodologies.
Offline-first Flutter voting app with tamper-evident vote chains, JWT/HMAC auth and WebSocket real-time results. Engineering thesis.
Web Apps book store for the course of secure software dev
Secure Software Development, Software Architecture, OOP, Software Product Line, UML Modeling
Python-based secure coding review project demonstrating vulnerability identification and remediation techniques.
Building strong foundations in secure software development.
CI gates that carry evidence of having gone red on a real defect, and the same rules as an agent skill: 92 production-discipline rules, each with the incident behind it — part of them decided by the bundle's own checkers, the rest written for an agent to read; latest v0.10.0, Python 3.11+, archived under a DOI.
To associate your repository with the secure-software-development topic, visit your repo's landing page and select "manage topics."