DevSecOps
Tools for implementing DevSecOps
Development
Git Secrets - Prevents you from committing secrets and credentials into git repositories
Security plugins (Snyk, Fortify, Veracode) in any IDE (VSCode, IntelliJ)
Trufflehog - Find and verify credentials
Security (Application Security Testing)
Code Quality - SonarQube, CodeQL
SAST Security (Static) - Veracode, Chackmarx, Fortify
Software Composition Analysis (SCA) Security - Fortify, Veracode, Blackduck, Snyk
DAST (Dynamic) Security - OWASP ZAP, BurpSuite, WebInspect, Veracode DAST, Acunetix
Infrastructure as Code (IaC) Security - Bridgecrew, Snyk
Container Security - AQUA, Qualys, Prisma Cloud
Operations
Pipeline Building - Jenkins, Azure DevOps, GCP CludBuild, AWS, GitHub Actions, GitLab
Cloud Security Posture Management - AQUA, BridgeCrew
Container Registry Scanning - AQUA, AWS Native Registry
Infrastructure Scanning Tools - Chief Inspec (Compliance), Nessus
Cloud Security - Azure Defense, AWS Security Hub
Last updated