Skip to content
#

ci-cd-security

Here are 26 public repositories matching this topic...

Defensive static analysis and detection engineering for the 2026 Shai-Hulud npm supply-chain campaign: Sigma/YARA rules, IOCs, ATT&CK mapping, and defender guidance.

  • Updated Aug 4, 2026
  • YARA

Offline Jenkins credential decryption tool for post-exploitation, red team operations, and CTFs. Decrypts credentials.xml using master.key and hudson.util.Secret without a running Jenkins instance. Supports legacy and modern encryption formats, with Docker and cross-platform support

  • Updated Jan 20, 2026
  • Python

Evidence-first prompt toolkit for AI-assisted supply chain security audits across npm, Composer, CI/CD, GitHub Actions, Next.js, Vercel, TanStack, containers, SaaS/OAuth and LGPD incident response.

  • Updated May 29, 2026
  • PowerShell

A production-style DevSecOps CI/CD pipeline demonstrating shift-left security with open-source tools. It performs SAST, secrets detection, dependency and container scanning, SBOM generation, and image signing before deploying to Kubernetes. The pipeline can run locally or via GitHub Actions and generates security reports for validation.

  • Updated Mar 13, 2026
  • Shell

ᴄʏʙᴇʀ ꜱᴋʏ: ᴀɴ ᴀᴜᴛᴏɴᴏᴍᴏᴜꜱ, ᴀʟʟ-ɪɴ-ᴏɴᴇ ᴀꜱᴘᴍ & ᴄꜱᴘᴍ ᴘʟᴀᴛꜰᴏʀᴍ ᴜɴɪꜰʏɪɴɢ 15+ ꜱᴄᴀɴɴᴇʀꜱ (ꜱᴀꜱᴛ, ᴅᴀꜱᴛ, ꜱᴄᴀ, ɪᴀᴄ) ɪɴᴛᴏ ᴀ ꜱɪɴɢʟᴇ ᴏʀᴄʜᴇꜱᴛʀᴀᴛɪᴏɴ ʟᴏᴏᴘ. ꜰᴇᴀᴛᴜʀᴇꜱ ᴀɢᴇɴᴛɪᴄ ᴀɪ ᴘᴇɴᴇᴛʀᴀᴛɪᴏɴ ᴛᴇꜱᴛɪɴɢ ᴛᴏ ᴠᴀʟɪᴅᴀᴛᴇ ᴇxᴘʟᴏɪᴛꜱ, ꜰɪʟᴛᴇʀ ꜰᴀʟꜱᴇ ᴘᴏꜱɪᴛɪᴠᴇꜱ, ᴀɴᴅ ᴅᴇᴘʟᴏʏ ᴀᴜᴛᴏꜰɪx ʀᴇᴍᴇᴅɪᴀᴛɪᴏɴ ᴘᴀᴛᴄʜᴇꜱ ɴᴀᴛɪᴠᴇʟʏ ɪɴ ᴄɪ/ᴄᴅ ᴘɪᴘᴇʟɪɴᴇꜱ, ʀᴜɴᴛɪᴍᴇ ᴇɴᴠɪʀᴏɴᴍᴇɴᴛꜱ, ᴀɴᴅ ᴅᴇᴠᴇʟᴏᴘᴇʀ ᴡᴏʀᴋꜱᴛᴀᴛɪᴏɴꜱ.

  • Updated May 14, 2026
  • TypeScript

Improve this page

Add a description, image, and links to the ci-cd-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the ci-cd-security topic, visit your repo's landing page and select "manage topics."

Learn more