A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.
-
Updated
Aug 6, 2026 - Go
A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.
GPU-accelerated secret scanner for code, Git history, containers, cloud, browser assets, and CI. 923 detectors, live verification, CUDA, Metal, WGPU.
Static security scanner and linter for GitLab CI. Finds .gitlab-ci.yml misconfigurations, supply-chain risks, and leaked secrets. Offline, SARIF output, OWASP CICD-SEC and CWE mappings.
Defensive static analysis and detection engineering for the 2026 Shai-Hulud npm supply-chain campaign: Sigma/YARA rules, IOCs, ATT&CK mapping, and defender guidance.
CLI Vulnify - Faz o scan em seus projetos buscando por vulnerabilidades.
Comprehensive guide for configuring Role-Based Access Control (RBAC) in Jenkins using the Role Strategy Plugin.
Go supply chain security analysis – finds vulnerabilities, weak maintainers, typosquatting, and CI/CD risks. SBOM + enterprise PDF reports.
Offline Jenkins credential decryption tool for post-exploitation, red team operations, and CTFs. Decrypts credentials.xml using master.key and hudson.util.Secret without a running Jenkins instance. Supports legacy and modern encryption formats, with Docker and cross-platform support
Jenkins plugin for Xygeni - End to end software development and delivery security
Git-native secrets manager for teams and AI agents: age encryption, deterministic diffs, leak prevention, secure runtime injection. Dual-licensed MIT OR Apache-2.0.
Multi-gate open source supply chain trust validation pipeline with zero-day CVE expedited lane
Hands-on demo for the OSS Trust Framework — 6 scenarios including live CVE detection, IronWorm and Miasma behavioral pattern matching, and a full zero-day MFA quorum workflow. 131 passing tests · all offline.
Evidence-first prompt toolkit for AI-assisted supply chain security audits across npm, Composer, CI/CD, GitHub Actions, Next.js, Vercel, TanStack, containers, SaaS/OAuth and LGPD incident response.
Production-grade DevSecOps pipeline with automated vulnerability scanning
Production-grade DevSecOps project implementing a secure CI/CD pipeline with automated security scanning, container hardening, Kubernetes deployment, and cloud-native security practices.
A production-style DevSecOps CI/CD pipeline demonstrating shift-left security with open-source tools. It performs SAST, secrets detection, dependency and container scanning, SBOM generation, and image signing before deploying to Kubernetes. The pipeline can run locally or via GitHub Actions and generates security reports for validation.
Pre-clone repo security scanner. Detects obfuscated payloads, hardcoded secrets, Unicode tricks, typo-squatting, CI/CD abuse, and supply-chain attacks before you clone.
Advanced CI/CD supply-chain risk analyzer with dependency confusion detection, policy-as-code, SARIF, OSV intelligence, dashboard, and Docker deployment.
ᴄʏʙᴇʀ ꜱᴋʏ: ᴀɴ ᴀᴜᴛᴏɴᴏᴍᴏᴜꜱ, ᴀʟʟ-ɪɴ-ᴏɴᴇ ᴀꜱᴘᴍ & ᴄꜱᴘᴍ ᴘʟᴀᴛꜰᴏʀᴍ ᴜɴɪꜰʏɪɴɢ 15+ ꜱᴄᴀɴɴᴇʀꜱ (ꜱᴀꜱᴛ, ᴅᴀꜱᴛ, ꜱᴄᴀ, ɪᴀᴄ) ɪɴᴛᴏ ᴀ ꜱɪɴɢʟᴇ ᴏʀᴄʜᴇꜱᴛʀᴀᴛɪᴏɴ ʟᴏᴏᴘ. ꜰᴇᴀᴛᴜʀᴇꜱ ᴀɢᴇɴᴛɪᴄ ᴀɪ ᴘᴇɴᴇᴛʀᴀᴛɪᴏɴ ᴛᴇꜱᴛɪɴɢ ᴛᴏ ᴠᴀʟɪᴅᴀᴛᴇ ᴇxᴘʟᴏɪᴛꜱ, ꜰɪʟᴛᴇʀ ꜰᴀʟꜱᴇ ᴘᴏꜱɪᴛɪᴠᴇꜱ, ᴀɴᴅ ᴅᴇᴘʟᴏʏ ᴀᴜᴛᴏꜰɪx ʀᴇᴍᴇᴅɪᴀᴛɪᴏɴ ᴘᴀᴛᴄʜᴇꜱ ɴᴀᴛɪᴠᴇʟʏ ɪɴ ᴄɪ/ᴄᴅ ᴘɪᴘᴇʟɪɴᴇꜱ, ʀᴜɴᴛɪᴍᴇ ᴇɴᴠɪʀᴏɴᴍᴇɴᴛꜱ, ᴀɴᴅ ᴅᴇᴠᴇʟᴏᴘᴇʀ ᴡᴏʀᴋꜱᴛᴀᴛɪᴏɴꜱ.
Frozen same-owner source-to-artifact admission evidence: completed A-G rounds with detached verification; not publication, deployment, or independent review.
Add a description, image, and links to the ci-cd-security topic page so that developers can more easily learn about it.
To associate your repository with the ci-cd-security topic, visit your repo's landing page and select "manage topics."