A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.
-
Updated
Oct 3, 2026 - Go
A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.
zanadir is an open-source CLI tool that analyzes GitHub repositories and suggests open-source tools to enhance CI/CD best practices.
Welcome to the "Secure Pipeline" workshop! This hands-on workshop teaches you how to build a comprehensive security-focused CI/CD pipeline with multiple layers of security scanning and best practices.
Static security scanner and linter for GitLab CI. Finds .gitlab-ci.yml misconfigurations, supply-chain risks, and leaked secrets. Offline, SARIF output, OWASP CICD-SEC and CWE mappings.
JenkinsBreaker: Offensive CI/CD security research framework focused on Jenkins exploitation, CVE chaining, and pipeline compromise scenarios.
🛡️ A modern DevSecOps CI/CD pipeline dashboard and security portal. Monitors codebases using multi-layered scanners (GitLeaks, Trivy, Semgrep, Bandit) and generates isolated HTML vulnerability reports. Built with React, Vite, Express, and MongoDB.
CI/CD Pipeline Security Audit Lab - Hands-on exercise for Software and Data Integrity Failures (OWASP A08:2021). Part of Dibimbing.id cybersecurity bootcamp.
A Dagger module for automated container security auditing. Integrates with Trivy, Grype, and Snyk to perform vulnerability scans, enforce best practices, and generate compliance reports for CI/CD pipelines.
CI/CD pipeline security analyzer — scans GitHub Actions workflows for attack vectors and maps findings to MITRE ATT&CK
Materials from The Data Engineering Academy
Reusable Terraform CI/CD pipeline template for Azure DevOps with integrated IaC security checks (Checkov) and vulnerability scanning (Trivy).
Reference workflows, scripts, and templates for hardening CI/CD pipelines with Sigstore, SLSA, and SBOMs.
Pre-pipeline inspection library and CLI tool for CSV/TSV files powered by bytesense. Detects broken encodings, malformed structures, and contract violations offline before data reaches your DataFrames.
Fork reference — Veracode GitHub Workflow Integration — repo scanning pipeline reference
Repository untuk tugas DevSecOps Week5 — SAST & DAST
The lightweight Python CLI that scans your repository for risky CI/CD workflows, insecure Dockerfiles, and common DevOps configuration mistakes
DevSecOps CI/CD pipeline scanner — Jenkins, GitHub Actions, GitLab, Azure Pipelines
Secure CI/CD pipeline demonstrating artifact supply chain security using GitHub Actions, JFrog Artifactory, and Xray.
GitHub Actions pipeline that turns Trivy, tfsec, Snyk, and OWASP ZAP into automated pull-request gates blocking critical findings before merge.
Demonstrates insecure vs hardened CI/CD pipelines with secrets handling, least-privilege access, and security validation for DevSecOps.
To associate your repository with the pipeline-security topic, visit your repo's landing page and select "manage topics."