#1Security integration in CI/CD pipelines, shift-left, and DevOps security automation tools.
Kitploit recommended

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

A software supply chain framework powered by Nix.

Project Aura: Security auditing and code introspection

kubeaudit helps you audit your Kubernetes clusters against common security controls

Infrastructure Automation

Open source compliance tool for development platforms.

KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems

Identify hardcoded secrets in static structured text

Static Token And Credential Scanner


A static analysis tool for securing Go code

Open Cloud Security Posture Management Engine

A self-hosted Fuzzing-As-A-Service platform

A service that analyzes docker images and scans for vulnerabilities

kube-scan: Octarine k8s cluster risk assessment tool

The Secure Coding Framework