cyberstars
cyberstars / purpose / devsecops

Outils pour devsecops

Shift-left scanning in CI/CD pipelines.

54 tools indexed

Open-source web app scanner.

ScanInterceptWeb apps
JavaApache-2.0

Policy-as-code across the stack.

HardenAutomateCloudIaC
GoApache-2.0

Multi-cloud security posture.

ScanHardenCloud
PythonApache-2.0

QARK

Quick Android Review Kit.

ScanAnalyzeMobile apps
PythonApache-2.0

Detect vulnerable JS libraries.

ScanWeb appsSource code
JavaScriptApache-2.0

Self-hosted open-source WAF.

MonitorHardenWeb apps
GoApache-2.0

API fuzzer from OpenAPI/GraphQL.

FuzzScanWeb apps
PythonMIT

Lightweight static analysis.

ScanAnalyzeSource code
OCamlLGPL-2.1

Solidity / Vyper static analyzer.

ScanAnalyzeSource code
PythonAGPL-3.0

Open-source SCA + IaC scanner.

ScanAnalyzeSource codeCloud
TypeScriptApache-2.0

Solidity inspector.

AnalyzeSource code
JavaScriptApache-2.0

Syft

Generate SBOMs from containers and source code.

AnalyzeCloudSource code
GoApache-2.0

Cloud-native secrets manager.

HardenAutomateCloudSource code
RustApache-2.0

eBPF-based runtime security.

MonitorHardenCloudEndpoints
GoApache-2.0

Cross-platform data-protection framework.

HardenSource codeEndpoints
CApache-2.0

Open-source cloud-native protection platform.

ScanMonitorCloudIaC
JavaScriptApache-2.0

Container and IaC vulnerability scanner.

ScanCloudIaC
GoApache-2.0

Find leaked credentials at scale.

ScanSource codeCloud
GoAGPL-3.0

Google's network vulnerability scanner.

ScanNetworksWeb apps
JavaApache-2.0

Vuls

Agent-less Linux vulnerability scanner.

ScanEndpointsCloud
GoGPL-3.0

Pre-commit secret detection.

ScanSource code
PythonApache-2.0

LLM vulnerability scanner.

ScanFuzzWeb appsSource code
PythonApache-2.0

Golang security checker.

ScanAnalyzeSource code
GoApache-2.0

Google's general-purpose fuzzer.

FuzzBinariesSource code
CApache-2.0
Best cybersecurity tools for DevSecOps — 2026 · CyberStars