awesome-oss-devsec

Security toolkit

A curated list of security tools and principles for developers.

An awesome list of OSS developer-first security tools

GitHub

172 stars
6 watching
13 forks
last commit: about 2 years ago
Linked from 1 awesome list

developer-securityhacktoberfesthacktoberfest2022open-sourcesecuritysecurity-tools

:!last-update-label: :compat-mode!: Awesome Open-Source Developer Security Tools

https://mvsp.dev/mvsp.en/index.html[MVSPRespond to security reports within a reasonable time frame | * 1.1]
https://mvsp.dev/mvsp.en/index.html[MVSPEnsure non-production environments do not contain production data | * 1.2]
https://mvsp.dev/mvsp.en/index.html[MVSPComply with local laws and regulations in jurisdictions applicable to your company and your customers, such as GDPR, Binding Corporate Rules, and Standard Contractual Clauses | * 1.6]
https://github.com/deepfence/ThreatMapper[DeepfenceSOC2 | * ThreatMapper]
https://hub.steampipe.io/mods?objectives=compliance[SteampipeCompliance Mods]
https://mvsp.dev/mvsp.en/index.html[MVSPInclude the following information in the notification: ** Relevant point of contact ** Preliminary technical analysis of the breach ** Remediation plan with reasonable timelines | * 1.7]
https://github.com/boxyhq/jackson[BoxyHQSOC2 CC6.1 | * SAML Jackson]
https://www.aserto.com[Aserto]SOC2 CC6.1 | *
https://github.com/boxyhq/jackson#directory-sync[BoxyHQ1,886almost 2 years agoDirectory Sync]
https://github.com/casbin/casbin[Casbin]
https://cerbos.dev[Cerbos]
https://github.com/ory/keto[Keto]
https://github.com/osohq/oso[Oso]
https://mvsp.dev/mvsp.en/index.html[MVSPInclude the Strict-Transport-Security header on all pages with the directive | * 2.2]
https://hub.steampipe.io/plugins/turbot/net[SteampipeSOC2 CC6.7 | * Net Plugin]
https://github.com/drwetter/testssl.sh[testssl.sh]
https://owasp.org/www-project-dependency-check[OWASPSOC2 CC7.1 | * Dependency Check]
https://owasp.org/www-project-dependency-track[OWASPDependency Track]
https://github.com/retracedhq[BoxyHQSOC2 CC7.2 | * Audit Logs]
https://www.elastic.co/elastic-stack[ELKStack]
https://www.fluentd.org[FluentD]
https://steampipe.io[Steampipe]
https://mvsp.dev/mvsp.en/index.html[MVSPPeriodically test backup restoration | * 2.8]
https://github.com/Bearer/bearer[Bearer]
https://mvsp.dev/mvsp.en/index.html[MVSPUse of vulnerable libraries | * 3.3]
https://owasp.org/www-project-top-ten[OWASPSOC2 CC7.1 | * Top Ten]
https://owasp.org/www-project-zap/[OWASPZap]
https://hub.steampipe.io/mods/turbot/net_insights[SteampipeNet Insights mod]
https://wapiti-scanner.github.io[WapitiScanner]
https://github.com/Bearer/bearer[Bearer]
https://github.com/bridgecrewio/AirIAM[AirIAM]SOC2 CC7.1 | *
https://github.com/aquasecurity/cloudsploit[Cloudsploit]
https://github.com/deepfence/ThreatMapper[DeepfenceThreatMapper]
https://github.com/controlplaneio/kubesec[KubesecKubernetes security]
https://github.com/prowler-cloud/prowler[Prowlerfor AWS]
https://hub.steampipe.io/mods?objectives=compliance,security[SteampipeCompliance & Security mods]
https://github.com/aquasecurity/trivy[Trivycontainer scanner]
https://github.com/GitGuardian/ggshield[GitGuardian]SOC2 CC7.1 | *
https://github.com/zricethezav/gitleaks[Gitleaks]
https://hub.steampipe.io/plugins/turbot/code[SteampipeCode Plugin]
https://github.com/Bearer/bearer[Bearer]

Backlinks from these awesome lists:

0