Skip to content
#

ci-cd-security

Here are 26 public repositories matching this topic...

Defensive static analysis and detection engineering for the 2026 Shai-Hulud npm supply-chain campaign: Sigma/YARA rules, IOCs, ATT&CK mapping, and defender guidance.

  • Updated Aug 4, 2026
  • YARA

Offline Jenkins credential decryption tool for post-exploitation, red team operations, and CTFs. Decrypts credentials.xml using master.key and hudson.util.Secret without a running Jenkins instance. Supports legacy and modern encryption formats, with Docker and cross-platform support

  • Updated Jan 20, 2026
  • Python

Evidence-first prompt toolkit for AI-assisted supply chain security audits across npm, Composer, CI/CD, GitHub Actions, Next.js, Vercel, TanStack, containers, SaaS/OAuth and LGPD incident response.

  • Updated May 29, 2026
  • PowerShell

A production-style DevSecOps CI/CD pipeline demonstrating shift-left security with open-source tools. It performs SAST, secrets detection, dependency and container scanning, SBOM generation, and image signing before deploying to Kubernetes. The pipeline can run locally or via GitHub Actions and generates security reports for validation.

  • Updated Mar 13, 2026
  • Shell

Spirl is a non-human identity and access management (IAM) startup that in 2025 rebranded to Defakto (defakto.security); spirl.com now redirects to the Defakto site. The company secures automated systems — workloads, services, CI/CD pipelines, Kubernetes, and AI agents — by replacing static secrets and hardcoded credentials with short-lived…

  • Updated Aug 8, 2026

Improve this page

Add a description, image, and links to the ci-cd-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the ci-cd-security topic, visit your repo's landing page and select "manage topics."

Learn more