DevSecOps & Pipeline Security
Tools for integrating security into the development pipeline and DevOps processes.
Tools
Fortify on Demand
DevSecOps & Pipeline SecurityA cloud-based application security service that integrates security testing into the DevOps toolchain.
PagerDuty Full Service Ownership Documentation
DevSecOps & Pipeline Securityguide to help teams transition to a full-service ownership model.
JFrog Xray
DevSecOps & Pipeline SecurityA software composition analysis (SCA) solution that identifies vulnerabilities in open-source components and license compliance violations.
PagerDuty DevSecOps Documentation
DevSecOps & Pipeline SecurityA guide for integrating security into the development and operations lifecycle, emphasizing the importance of early security checks and cross-team collaboration.
TerraGoat
DevSecOps & Pipeline SecurityTerraGoat is a Terraform repository designed to demonstrate common configuration errors in cloud environments.
Hammer
DevSecOps & Pipeline SecurityDow Jones Hammer : Protect the cloud with the power of the cloud(AWS)
Pulumi
DevSecOps & Pipeline SecurityPulumi is an Infrastructure as Code (IaC) platform that allows developers to manage cloud resources using familiar programming languages.
SecHub
DevSecOps & Pipeline SecurityA unified integration mechanism for managing multiple security tools and scanners through a simple API/client interface.
Anchore DevSecOps
DevSecOps & Pipeline SecurityA solution for integrating security measures throughout the software development lifecycle, focusing on vulnerability scanning, secrets detection, and malware identification.
CloudWorks
DevSecOps & Pipeline SecurityCloudWorks is a cloud security tool developed by the Air Force Research Laboratory that focuses on securing software development and deployment.
SonarQube
DevSecOps & Pipeline SecurityA robust static code analysis tool for maintaining high code quality and security in software projects.