Open Source DevSecOps Tools
DevSecOps integrates security practices into software development and operations rather than treating them as a final review. It helps teams identify and address risks throughout the software lifecycle, from planning and coding to building, deploying, and monitoring applications. Automating checks can make security feedback faster and more consistent while supporting collaboration among developers, security specialists, and operations teams.
Open source DevSecOps tools include code and dependency scanners, secret detection, infrastructure checks, container security, policy enforcement, and vulnerability management. When choosing tools, consider their maturity, license, maintenance activity, supported languages and platforms, integration with existing workflows, and infrastructure requirements. They can be useful to software teams of any size, security practitioners, platform engineers, and organizations seeking more transparent, adaptable security processes.
4 repositories · updated September 8, 2026

GuardVibe: AI-Native Security for Your Code, From Prompt to Production
GuardVibe is a security infrastructure designed specifically for AI-generated code. It provides deterministic, daily CVE intelligence, whole-repo context, and independent verification, addressing gaps that AI coding agents cannot fill. GuardVibe shifts security left by analyzing prompts before code generation, ensuring robust protection throughout the development lifecycle.

Awesome Threat Modelling: A Curated List of Security Resources
Awesome Threat Modelling is a comprehensive GitHub repository offering a curated list of resources for learning and practicing threat modeling. It includes books, courses, videos, tools, and tutorials, making it an invaluable guide for anyone interested in security review and DevSecOps. This repository serves as an excellent starting point for both beginners and experienced professionals looking to enhance their security understanding.

vuln-bank: A Deliberately Vulnerable Banking App for Security Testing
vuln-bank is a Python-based banking application intentionally built with a wide array of security vulnerabilities. It serves as an excellent hands-on platform for security professionals, developers, and enthusiasts to practice web, API, and AI application security testing. This project is ideal for learning about common exploits, secure coding practices, and DevSecOps implementation in a controlled environment.

Netmaker: Automating Secure WireGuard VPNs for Any Environment
Netmaker simplifies the creation and management of secure virtual networks using WireGuard. It automates fast, distributed, and encrypted connections across various environments, from homelabs to enterprise infrastructure. This powerful tool streamlines network deployment for remote access, site-to-site, and mesh VPN configurations.