DevSecOps & Pipeline Security
Tools for integrating security into the development pipeline and DevOps processes.
Tools
Bridgecrew
DevSecOps & Pipeline SecurityBridgecrew automates the identification and remediation of misconfigurations in cloud infrastructure, leveraging its open-source tool Checkov for static analysis of IaC templates.
zizmor
DevSecOps & Pipeline SecurityA static analysis tool for GitHub Actions that identifies common security issues in CI/CD setups.
Mend.io
DevSecOps & Pipeline SecurityMend.io is a platform that integrates security into the software development lifecycle, focusing on open-source dependencies and codebases.
KICS
DevSecOps & Pipeline SecurityFind security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Checkmarx SAST
DevSecOps & Pipeline SecurityA static application security testing tool that identifies and mitigates security vulnerabilities early in the software development life cycle.
DefectDojo
DevSecOps & Pipeline SecurityA unified DevSecOps platform for managing vulnerabilities and security posture across multiple tools and projects.
Snyk Cloud
DevSecOps & Pipeline SecuritySnyk Cloud secures cloud environments by integrating security checks into the development lifecycle, automating scans and continuous monitoring of cloud configurations.
Terrascan
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
Snyk Cloud Security
DevSecOps & Pipeline SecurityA platform for securing cloud-native applications and infrastructure by integrating security into the software development lifecycle.
tfsec
DevSecOps & Pipeline SecurityA security scanner for Terraform configurations that identifies potential vulnerabilities through static analysis.
Spectral
DevSecOps & Pipeline SecurityA DevSecOps tool that integrates security into the software development lifecycle, focusing on secret protection and code security.
Checkov
DevSecOps & Pipeline SecurityCheckov is a static code analysis tool for infrastructure-as-code (IaC) configurations, ensuring security and compliance across various cloud platforms.