<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>devsecops</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/451/feed"/>
    <updated>2026-08-02T19:49:06+00:00</updated>
    <id>https://links.biapy.com/guest/tags/451/feed</id>
            <entry>
            <id>https://links.biapy.com/links/13387</id>
            <title type="text"><![CDATA[rnsec]]></title>
            <link rel="alternate" href="https://www.rnsec.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13387"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Lightweight &amp;amp; Fast Security Scanner for React Native &amp;amp; Expo.

A zero-configuration security scanner for React Native and Expo applications that detects vulnerabilities, hardcoded secrets, and security misconfigurations with a single command.

- [rnsec @ GitHub](https://github.com/adnxy/rnsec).]]>
            </summary>
            <updated>2026-07-23T15:42:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13372</id>
            <title type="text"><![CDATA[Kingfisher]]></title>
            <link rel="alternate" href="https://mongodb.github.io/kingfisher/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13372"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source Secret Scanner with Live Validation

Detect, validate, and revoke leaked credentials across your codebase, Git history, cloud storage, and developer platforms. Built in Rust by MongoDB. 

- [Kingfisher @ GitHub](https://github.com/mongodb/kingfisher).]]>
            </summary>
            <updated>2026-07-23T05:57:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13328</id>
            <title type="text"><![CDATA[Bumblebee Hive]]></title>
            <link rel="alternate" href="https://github.com/radioactivetobi/bumblebee-hive" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13328"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fleet visibility dashboard and ingest server for Bumblebee scans.

Run the Hive server, point developer endpoints at it with --output http, and browse fleet inventory, exposure findings, and per-endpoint scan history in a React dashboard — no log shipper or custom receiver required.

 Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.]]>
            </summary>
            <updated>2026-07-20T04:57:05+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13327</id>
            <title type="text"><![CDATA[vsix-audit]]></title>
            <link rel="alternate" href="https://github.com/trailofbits/vsix-audit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13327"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security scanner for VS Code extensions.

Security scanner for VS Code extensions. Detects malicious extensions before installation by analyzing code patterns, indicators of compromise, and known malware signatures.]]>
            </summary>
            <updated>2026-07-20T04:53:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13296</id>
            <title type="text"><![CDATA[HASP]]></title>
            <link rel="alternate" href="https://gethasp.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13296"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hand the agent the keys.
Without actually handing it the keys.
 HASP is a local-first broker for managed secrets in agent workflows.

A local broker that holds your secrets in one encrypted vault and hands them to apps and coding agents when needed, only inside the project boundary, only for the window you allow, and never as a value the agent can see.

Agents need credentials to run tests, call APIs, and deploy code. Copying those credentials into prompts, shell history, .env files, or repo-local notes makes the agent faster today and harder to trust tomorrow. HASP keeps secrets in a local encrypted vault and gives commands only the values they are allowed to use at runtime.

- [HASP @ GitHub](https://github.com/gethasp/hasp).]]>
            </summary>
            <updated>2026-07-15T08:29:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13290</id>
            <title type="text"><![CDATA[Dotenvx]]></title>
            <link rel="alternate" href="https://dotenvx.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13290"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[a secure dotenv–from the creator of dotenv.

- [Dotenvx @ GitHub](https://github.com/dotenvx/dotenvx).]]>
            </summary>
            <updated>2026-07-15T07:49:07+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13246</id>
            <title type="text"><![CDATA[gh-workflow-hardener]]></title>
            <link rel="alternate" href="https://github.com/indoor47/gh-workflow-hardener" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13246"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[GitHub Actions security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities. 

Secure your GitHub Actions workflows against supply chain attacks. Detects unpinned actions (the tj-actions attack vector), dangerous permissions, and script injection — all in one scan.]]>
            </summary>
            <updated>2026-07-09T07:00:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13237</id>
            <title type="text"><![CDATA[replacements.fyi]]></title>
            <link rel="alternate" href="https://replacements.fyi/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13237"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[performant, safer npm package alternatives.

type a package name. we&amp;#039;ll tell you what you don&amp;#039;t need.
The module replacements project is a community-driven effort to map replaceable npm packages to their native or more performant alternatives.

This website serves as a searchable, interactive catalog of these module replacements, allowing you to easily find and adopt better alternatives for your projects.

- [replacements.fyi @ GitHub](https://github.com/e18e/replacements.fyi).

Related contents:

- [\#1014 - Anthropic doesn’t use AI @ Syntax](https://syntax.fm/show/1014/anthropic-doesn-t-use-ai).]]>
            </summary>
            <updated>2026-07-07T05:49:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13193</id>
            <title type="text"><![CDATA[KICS]]></title>
            <link rel="alternate" href="https://docs.kics.io/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13193"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project.

-  [KICS @ GitHub](https://github.com/Checkmarx/kics/).

Related contents:

- [Top 7 Terraform Scanning Tools You Should Know in 2026 @ Spacelift](https://spacelift.io/blog/terraform-scanning-tools).]]>
            </summary>
            <updated>2026-07-03T07:55:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13155</id>
            <title type="text"><![CDATA[Kubernetes Security Profiles Operator]]></title>
            <link rel="alternate" href="https://github.com/kubernetes-sigs/security-profiles-operator" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13155"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Security Profiles Operator (SPO) is an out-of-tree Kubernetes enhancement which aims to make it easier to create and use SELinux, seccomp and AppArmor security profiles in Kubernetes clusters.

Related contents:

- [Security Profiles Operator v1: Stable APIs, Security Hardened, and Shaping Upstream Kubernetes @ CNCF](https://www.cncf.io/blog/2026/06/26/security-profiles-operator-v1-stable-apis-security-hardened-and-shaping-upstream-kubernetes/).]]>
            </summary>
            <updated>2026-06-29T10:55:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13102</id>
            <title type="text"><![CDATA[CVE Lite CLI]]></title>
            <link rel="alternate" href="https://owasp.org/cve-lite-cli/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13102"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scan. Understand. Fix.
Free, local-first JS/TS vulnerability scanner.

 Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance. 

Most security tools are built around pipelines, not developers. CVE Lite CLI scans your lockfile locally in seconds, explains the dependency path, and tells you what to update before you push.

- [CVE Lite CLI @ GitHub](https://github.com/OWASP/cve-lite-cli).

Related contents:

- [Cet outil open source traque les conseils de sécurité que l&amp;#039;IA vous a refilés et qui ne valent plus rien @ Korben :fr:](https://korben.info/cet-outil-open-source-traque-les-conseils-de-securite-que-lia-vous-a-refiles-et-qui-ne-valent-plus-rien.html).]]>
            </summary>
            <updated>2026-06-24T09:34:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13099</id>
            <title type="text"><![CDATA[helmsniff]]></title>
            <link rel="alternate" href="https://github.com/VahidR/helmsniff" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13099"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Go CLI tool that scans rendered Kubernetes/Helm manifests and produces a CSV &amp;amp; JSON report of security misconfigurations.]]>
            </summary>
            <updated>2026-06-23T12:48:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13040</id>
            <title type="text"><![CDATA[Fleebag]]></title>
            <link rel="alternate" href="https://github.com/GuillaumeRoss/fleebag" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13040"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Deploy bagel to developer Macs via macOS PKG and surface secret-scanning results in Fleet.

fleebag packages the bagel open-source secret scanner into a macOS installer (.pkg) that runs automatically on developer laptops via a LaunchAgent. Scan results are written as JSON and queried by Fleet&amp;#039;s osquery agent, letting you see detected secrets across your entire fleet and enforce a compliance policy — all without touching each machine manually.

Related contents:

- [Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does @ Recyclebin.zip](https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel/).]]>
            </summary>
            <updated>2026-06-18T11:40:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12902</id>
            <title type="text"><![CDATA[External Secrets Operator]]></title>
            <link rel="alternate" href="https://external-secrets.io/main/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12902"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[External Secrets Operator is a Kubernetes operator that integrates external secret management systems like AWS Secrets Manager, HashiCorp Vault, Google Secrets Manager, Azure Key Vault, IBM Cloud Secrets Manager, CyberArk Secrets Manager, Pulumi ESC and many more. The operator reads information from external APIs and automatically injects the values into a Kubernetes Secret.

- [External Secrets Operator @ GitHub](https://github.com/external-secrets/external-secrets).

Related contents:

- [Discover the External Secret Operator (ESO) OVHcloud Provider to manage your Kubernetes secrets 🎉 @ OVHcloud Blog](https://blog.ovhcloud.com/discover-the-external-secret-operator-eso-ovhcloud-provider-to-manage-your-kubernetes-secrets-%f0%9f%8e%89/).]]>
            </summary>
            <updated>2026-06-03T10:09:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12877</id>
            <title type="text"><![CDATA[ghosttype]]></title>
            <link rel="alternate" href="https://github.com/xFreed0m/ghosttype" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12877"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
 
Local forensic scanner that extracts and verifies credentials from AI tool conversation history. Detection + verification powered by TruffleHog.]]>
            </summary>
            <updated>2026-06-01T15:50:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12854</id>
            <title type="text"><![CDATA[Bumblebee]]></title>
            <link rel="alternate" href="https://github.com/perplexityai/bumblebee" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12854"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.

 Related contents:

- [Perplexity Is Open-Sourcing Bumblebee @ Perplexity](https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee).
- [Perplexity open-sources Bumblebee security scanner @ AI News](https://www.testingcatalog.com/perplexity-open-sources-bumblebee-security-scanner/).]]>
            </summary>
            <updated>2026-05-26T12:45:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12804</id>
            <title type="text"><![CDATA[DockSec]]></title>
            <link rel="alternate" href="https://github.com/OWASP/DockSec" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12804"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-Powered Docker Security Analyzer.

AI-powered Docker security scanner that explains vulnerabilities in plain English]]>
            </summary>
            <updated>2026-05-21T11:59:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12657</id>
            <title type="text"><![CDATA[SmokedMeat]]></title>
            <link rel="alternate" href="https://github.com/boostsecurityio/smokedmeat" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12657"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A CI/CD Red Team Framework for demonstrating Build Pipeline security risks. 

SmokedMeat is a post-exploitation framework for CI/CD pipelines. Point it at a GitHub organization, let it find vulnerable workflows, deploy an implant to a compromised runner, then pivot through cloud providers, extract secrets, and map the blast radius - all from a terminal UI.

Related contents:

- [SmokedMeat: A Red Team Tool to Hack Your Pipelines First @ Boost Security Labs](https://labs.boostsecurity.io/articles/introducing-smokedmeat/).]]>
            </summary>
            <updated>2026-04-30T11:21:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12554</id>
            <title type="text"><![CDATA[Supply Chain Monitor]]></title>
            <link rel="alternate" href="https://github.com/elastic/supply-chain-monitor" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12554"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated monitoring of the top PyPI and npm packages for supply chain compromise. Polls both registries for new releases, diffs each release against its predecessor, and uses an LLM (via Cursor Agent CLI) to classify diffs as benign or malicious. Malicious findings trigger a Slack alert.

Related contents:

- [\#72 - Microsoft et Adobe corrigent une vulnérabilité déjà exploitée @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-72-microsoft-et-adobe-corrigent-une-vuln-rabilit-d-j-exploit-e).]]>
            </summary>
            <updated>2026-04-16T11:38:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12552</id>
            <title type="text"><![CDATA[aws-preflight]]></title>
            <link rel="alternate" href="https://github.com/gabrielPav/aws-preflight" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12552"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Check your AWS CLI commands for security risks before you run them. 

Security linter for AWS CLI commands. Catches misconfigurations before they hit your cloud.

703 security checks across 91 AWS services. Findings include severity ratings and a remediated command.

Related contents:

- [\#72 - Microsoft et Adobe corrigent une vulnérabilité déjà exploitée @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-72-microsoft-et-adobe-corrigent-une-vuln-rabilit-d-j-exploit-e).]]>
            </summary>
            <updated>2026-04-16T11:35:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12300</id>
            <title type="text"><![CDATA[Betterleaks]]></title>
            <link rel="alternate" href="https://betterleaks.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12300"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Better Secrets Scanner. Detect Leaked API Keys &amp;amp; Credentials.
 A Better Secrets Scanner built for configurability and speed.

Betterleaks is a tool for detecting secrets like passwords, API keys, and tokens in git repos, files, and whatever else you wanna throw at it via stdin. If you wanna learn more about how the detection engine works check out this blog: [Regex is (almost) all you need](https://lookingatcomputer.substack.com/p/regex-is-almost-all-you-need).

- [Betterleaks @ GitHub](https://github.com/betterleaks/betterleaks).

Related contents:

- [Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks @ aikido](https://www.aikido.dev/blog/betterleaks-gitleaks-successor).]]>
            </summary>
            <updated>2026-03-26T13:38:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12235</id>
            <title type="text"><![CDATA[Trajan]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/trajan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12235"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Trajan scans CI/CD pipelines for security vulnerabilities that attackers use to compromise software supply chains. It supports GitHub Actions, GitLab CI, Azure DevOps, Jenkins, and JFrog.]]>
            </summary>
            <updated>2026-03-23T14:22:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12104</id>
            <title type="text"><![CDATA[OneCLI]]></title>
            <link rel="alternate" href="https://onecli.sh/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12104"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Give your agents access, not your secrets.
The open-source secret vault for AI agents.
 Store once. Inject anywhere. Agents never see the keys. 

Open-source credential vault. Your agents call services and never see a key.

OneCLI is an open-source gateway that sits between your AI agents and the services they call. Instead of baking API keys into every agent, you store credentials once in OneCLI and the gateway injects them transparently. Agents never see the secrets.

- [OneCLI @ GitHub](https://github.com/onecli/onecli).]]>
            </summary>
            <updated>2026-07-24T12:29:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12097</id>
            <title type="text"><![CDATA[enject]]></title>
            <link rel="alternate" href="https://github.com/GreatScott/enject" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12097"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hide .env secrets from prAIng eyes.

secrets live in local encrypted stores (per project) and are injected directly into apps at runtime, never touching disk as plaintext. 

Related contents:

- [Don’t let A.I. read your .env files @ Filip Hric](https://filiphric.com/dont-let-ai-read-your-env-files).]]>
            </summary>
            <updated>2026-03-12T11:16:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12068</id>
            <title type="text"><![CDATA[Lade]]></title>
            <link rel="alternate" href="https://github.com/zifeo/lade" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12068"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automatically load secrets from your preferred vault as environment variables or files, and clear them once your shell command is over. 

Lade (/leɪd/) is a tool allowing you to automatically load secrets from your preferred vault into environment variables or files. It limits the exposure of secrets to the time the command requiring the secrets lives.

Related contents:

- [Lade : injecter les secrets automatiquement avec des hooks shell @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/secrets/lade/).]]>
            </summary>
            <updated>2026-03-09T10:26:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12050</id>
            <title type="text"><![CDATA[Aikido Safe Chain]]></title>
            <link rel="alternate" href="https://www.aikido.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12050"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Unified Security Platform from Code to Runtime.

 Protect against malicious code installed via npm, yarn, pnpm, npx, and pnpx with Aikido Safe Chain. Free to use, no tokens required. 

- [Aikido Safe Chain @ GitHub](https://github.com/AikidoSec/safe-chain).]]>
            </summary>
            <updated>2026-03-09T07:21:50+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11935</id>
            <title type="text"><![CDATA[git-agecrypt]]></title>
            <link rel="alternate" href="https://github.com/vlaci/git-agecrypt" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11935"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Git integration usable to store encrypted secrets in the git repository while having the plaintext available in the working tree. An alternative to git-crypt using age instead of GPG.

Do not use this tool unless you understand the security implications. I am by no mean a security expert and this code hasn&amp;#039;t been audited. Use at your own risk.]]>
            </summary>
            <updated>2026-02-27T06:41:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11933</id>
            <title type="text"><![CDATA[krops (krebs operations)]]></title>
            <link rel="alternate" href="https://github.com/krebs/krops" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11933"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[krops is a lightweight toolkit to deploy NixOS systems, remotely or locally.

-  [krops @ GitHub](https://github.com/krebs/krops).]]>
            </summary>
            <updated>2026-02-27T06:38:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11851</id>
            <title type="text"><![CDATA[CI/CD Cybersecurity Guide]]></title>
            <link rel="alternate" href="https://cybersecurity.cd.foundation/docs/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11851"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Implementing Open Source Security Tooling into your CI/CD Pipeline

Securing your Continuous Integration and Continuous Deployment (CI/CD) pipeline is no longer optional—it’s essential. This guide is your go-to resource for building, implementing, and optimizing secure CI/CD workflows. Whether you’re a developer, DevOps engineer, or security professional, we provide information on the open-source tools and guidance you need to model security at every stage of your pipeline. From securing code and builds to monitoring post-deployment environments, our hub empowers teams to integrate security seamlessly into their workflows without sacrificing speed or agility. Explore, learn, and transform your CI/CD processes into a fortress of innovation and resilience.

- [CI/CD Cybersecurity Guide @ GitHub](https://github.com/cdfoundation/CICD-Cybersecurity).

Related contents:

- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).]]>
            </summary>
            <updated>2026-02-18T13:15:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11712</id>
            <title type="text"><![CDATA[Plumber]]></title>
            <link rel="alternate" href="https://getplumber.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11712"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OpenSource compliance CLI for GitLab CI/CD.

Analyze your GitLab CI/CD pipelines for security and compliance: pipeline composition (templates, components, version constraints), container images (mutable tags, trusted registries), and branch protection settings.

Plumber is a compliance scanner for GitLab. It reads your .gitlab-ci.yml and repository settings, then checks for security and compliance issues.

- [Plumber @ GitHub](https://github.com/getplumber/plumber).

Related contents:

- [Plumber : Vos pipelines GitLab CI/CD sont-ils conformes ? @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/pipeline-cicd/gitlab/outils/plumber/).
- [Votre pipeline CI/CD GitLab a-t-il des fuites @ Korben :fr:](https://korben.info/plumber-scanner-securite-pipelines-cicd.html).]]>
            </summary>
            <updated>2026-04-13T09:23:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11624</id>
            <title type="text"><![CDATA[Brakeman]]></title>
            <link rel="alternate" href="https://brakemanscanner.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11624"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Brakeman Security Scanner. Secure Your Rails Applications

Brakeman is a free vulnerability scanner designed for Ruby on Rails applications. Statically analyze Rails application code to find security issues at any stage of development.

- [Brakeman @ GitHub](https://github.com/presidentbeef/brakeman).]]>
            </summary>
            <updated>2026-01-26T16:46:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11589</id>
            <title type="text"><![CDATA[Dotenv Mask Editor]]></title>
            <link rel="alternate" href="https://github.com/xinbenlv/dotenv-mask-editor" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11589"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secure visual editor for .env files that masks sensitive secrets while allowing easy editing.

Dotenv Mask Editor provides a table-based interface for .env files. It is designed to reduce the accidental exposure of sensitive values by masking strings that meet a length threshold. All processing is done locally within your editor.

Related contents:

- [Dotenv Mask Editor - Fini les clés API à l&amp;#039;air libre @ Korben :fr:](https://korben.info/dotenv-mask-editor.html).]]>
            </summary>
            <updated>2026-03-16T09:38:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11567</id>
            <title type="text"><![CDATA[lockenv]]></title>
            <link rel="alternate" href="https://github.com/illarion/lockenv" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11567"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Simple, CLI-friendly secret storage that lets you safely commit encrypted secrets to version control.

 Simple, password-based encrypted vault for .env and infrastructure secrets. Like git-crypt or sops, but dramatically simpler. Ideal for small teams and IaC workflows 

lockenv provides a secure way to store sensitive files (like .env files, configuration files, certificates) in an encrypted .lockenv file that can be safely committed to your repository. Files are encrypted using a password-derived key and can be easily extracted when needed.]]>
            </summary>
            <updated>2026-01-22T16:44:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11524</id>
            <title type="text"><![CDATA[envmap]]></title>
            <link rel="alternate" href="https://github.com/BinSquare/envmap" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11524"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[ENV management tool, consolidate and manage .env and env variables. 

Related contents:

- [Envmap - Fini les fichiers .env qui traînent et finissent sur GitHub @ Korben :fr:](https://korben.info/envmap-secrets-sans-fichier-env-disque-github-leaks.html).]]>
            </summary>
            <updated>2026-01-19T08:24:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11021</id>
            <title type="text"><![CDATA[github-update-secret]]></title>
            <link rel="alternate" href="https://github.com/mheap/github-update-secret" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11021"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Update a GitHub Secret in all your repos at the same time.

This CLI tool allows you to update the value of a GitHub Secret on multiple repositories at once. This is useful if you&amp;#039;re using a user account and not an org, as users do not have the concept of user level secrets.

Related contents:

- [Automated NPM secret rotation in GitHub Actions @ Michael Heap](https://michaelheap.com/rotate-all-npm-tokens-github-actions/).]]>
            </summary>
            <updated>2025-11-20T12:41:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10950</id>
            <title type="text"><![CDATA[Bytebase]]></title>
            <link rel="alternate" href="https://www.bytebase.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10950"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Database DevSecOps.

Bytebase is an open-source database DevOps tool, it&amp;#039;s the only database CI/CD project included by the CNCF Landscape and Platform Engineering.
It offers a web-based collaboration workspace to help DBAs and Developers manage the lifecycle of application database schemas.

- [Bytebase @ GitHub](https://github.com/bytebase/bytebase).

Related contents:

- [Digest \#187: AWS Alternatives, AI-Driven DevOps, Airbnb Runs Kubernetes at Scale and Terraform Drift Detection @ DevOps Bulletin](https://www.devopsbulletin.com/p/digest-187-aws-alternatives-ai-driven).]]>
            </summary>
            <updated>2025-11-13T06:41:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10840</id>
            <title type="text"><![CDATA[fnox]]></title>
            <link rel="alternate" href="https://fnox.jdx.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10840"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fort Knox for your secrets.  encrypted/remote secret manager.

Manage secrets with encryption or cloud providers - or both!

- [🔐 fnox @ GitHub](https://github.com/jdx/fnox).

Related contents:

- [Fnox - Le Fort Knox de vos secrets de dev @ Korben :fr:](https://korben.info/fnox-gestionnaire-de-secrets-dev.html).
- [Mise-en-place &amp;amp; Fnox : mon setup de gestion multi-projets @ Rémi Tech Notes :fr:](https://www.vrchr.fr/posts/2026/04/28/mise-en-place-fnox-setup-multi-projets/).]]>
            </summary>
            <updated>2026-04-29T06:48:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10647</id>
            <title type="text"><![CDATA[CycloneDX]]></title>
            <link rel="alternate" href="https://cyclonedx.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10647"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CycloneDX Bill of Materials Standard.

CycloneDX is a modern standard for the software supply chain.

The International Standard for Bill of Materials (ECMA-424)
The OWASP Foundation and Ecma International Technical Committee for Software &amp;amp; System Transparency (TC54) drive the continued advancement of the specification.

- [CycloneDX BOM Standard @ GitHub](https://github.com/CycloneDX).

Related contents:

- [CycloneDX PHP Composer Plugin @ GitHub](https://github.com/CycloneDX/cyclonedx-php-composer).]]>
            </summary>
            <updated>2025-10-14T09:44:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10557</id>
            <title type="text"><![CDATA[Zarf]]></title>
            <link rel="alternate" href="https://zarf.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10557"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Airgap Native Package Manager for Kubernetes.  airplane mode for your application delivery.

A free open source tool that enables continuous software delivery on systems that are disconnected from the internet.
Zarf is a free and open source tool that enables declarative creation &amp;amp; distribution of software into air-gapped/constrained/standalone environments.
Zarf provides a way to package and deploy software in a way that is repeatable, secure, and reliable.

- [Zarf documentation](https://docs.zarf.dev/).
- [Zarf @ GitHub](https://github.com/zarf-dev/zarf).

Related contents:

- [Digest \#187: AWS Alternatives, AI-Driven DevOps, Airbnb Runs Kubernetes at Scale and Terraform Drift Detection @ DevOps Bulletin](https://www.devopsbulletin.com/p/digest-187-aws-alternatives-ai-driven).]]>
            </summary>
            <updated>2025-11-13T06:43:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10521</id>
            <title type="text"><![CDATA[Replik8s]]></title>
            <link rel="alternate" href="https://github.com/latacora/replik8s" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10521"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A modern open-source Kubernetes auditing and investigation tool.

Replik8s is a modern open-source Kubernetes auditing and investigation tool. It is designed to address the common limitations of traditional security tools, which rely on narrow data collection and predefined logic. RepliK8s allows cloning Kubernetes clusters and serving back exact replicas of the original data, as well as conducting analysis through a tool-agnostic query language.]]>
            </summary>
            <updated>2025-10-06T05:18:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10428</id>
            <title type="text"><![CDATA[cfn-nag]]></title>
            <link rel="alternate" href="https://github.com/stelligent/cfn_nag" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10428"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Linting tool for CloudFormation templates.
The cfn-nag tool looks for patterns in CloudFormation templates that may indicate insecure infrastructure.

Related contents:

- [How to Complete Infrastructure Code Reviews Like a PRO @ microtica](https://www.microtica.com/blog/how-to-complete-infrastructure-code-reviews-like-a-pro).]]>
            </summary>
            <updated>2025-09-29T06:25:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10427</id>
            <title type="text"><![CDATA[Prowler]]></title>
            <link rel="alternate" href="https://prowler.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10427"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source Cloud Security Tool.

 Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments &amp;amp; audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, ENS and more.

- [Prowler @ GitHub](https://github.com/prowler-cloud/prowler).

Related contents:

- [How to Complete Infrastructure Code Reviews Like a PRO @ microtica](https://www.microtica.com/blog/how-to-complete-infrastructure-code-reviews-like-a-pro).]]>
            </summary>
            <updated>2025-09-29T06:23:23+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10066</id>
            <title type="text"><![CDATA[Semgrep App Security Platform]]></title>
            <link rel="alternate" href="https://semgrep.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10066"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-assisted SAST, SCA and Secrets Detection.
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code. 

Semgrep is a fast, open-source, static analysis tool that searches code, finds bugs, and enforces secure guardrails and coding standards. Semgrep supports 30+ languages and can run in an IDE, as a pre-commit check, and as part of CI/CD workflows.

- [Sempgrep @ GitHub](https://github.com/semgrep/semgrep).

Related contents:

- [Keeping Secrets Out of Logs @ allan.reyes.sh](https://allan.reyes.sh/posts/keeping-secrets-out-of-logs/).
- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).]]>
            </summary>
            <updated>2026-02-18T13:12:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10036</id>
            <title type="text"><![CDATA[ChopChop]]></title>
            <link rel="alternate" href="https://github.com/michelin/ChopChop" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10036"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[ChopChop is a command-line tool for dynamic application security testing on web applications, initially written by the Michelin CERT.

Its goal is to scan several endpoints and identify exposition of services/files/folders through the webroot. Checks/Signatures are declared in a config file (by default: chopchop.yml), fully configurable, and especially by developers.]]>
            </summary>
            <updated>2025-09-08T08:17:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9994</id>
            <title type="text"><![CDATA[Codefather]]></title>
            <link rel="alternate" href="https://donedeal0.gitbook.io/codefather/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9994"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Codefather protects your codebase by controlling who can change what. Set authorization levels, lock down files, and enforce your rules—offline via CLI or online with GitHub Actions. 

- [Codefather @ GitHub](https://github.com/DoneDeal0/codefather).]]>
            </summary>
            <updated>2025-09-04T09:30:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/272</id>
            <title type="text"><![CDATA[SecretSpec]]></title>
            <link rel="alternate" href="https://secretspec.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/272"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Declarative secrets, every environment, any provider.

SecretSpec separates the declaration of what secrets an application needs from where they are stored, enabling portable applications that work across different secret storage backends without code changes.

- [SecretSpec @ GitHub](https://github.com/cachix/secretspec).

Related contents:

- [Announcing SecretSpec: Declarative Secrets Management @ devenv](https://devenv.sh/blog/2025/07/21/announcing-secretspec-declarative-secrets-management/).]]>
            </summary>
            <updated>2025-11-20T13:39:50+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/355</id>
            <title type="text"><![CDATA[Opengrep]]></title>
            <link rel="alternate" href="https://www.opengrep.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/355"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🔎 Static code analysis engine to find security issues in code. 
Opengrep, a fork of Semgrep, under the LGPL 2.1 license.

Opengrep is an ultra-fast static analysis tool for searching code patterns with the power of semantic grep. Analyze large code bases at the speed of thought with intuitive pattern matching and customizable rules. Find and fix security vulnerabilities, fast – ship more secure code.

Opengrep supports 30+ languages, including:

Apex · Bash · C · C++ · C# · Clojure · Dart · Dockerfile · Elixir · HTML · Go · Java · JavaScript · JSX · JSON · Julia · Jsonnet · Kotlin · Lisp · Lua · OCaml · PHP · Python · R · Ruby · Rust · Scala · Scheme · Solidity · Swift · Terraform · TypeScript · TSX · YAML · XML · Generic (ERB, Jinja, etc.)

- [Opengrep @ GitHub](https://github.com/opengrep/opengrep).
- [Opengrep Rules @ GitHub](https://github.com/opengrep/opengrep-rules).]]>
            </summary>
            <updated>2026-01-21T08:58:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/393</id>
            <title type="text"><![CDATA[varlock]]></title>
            <link rel="alternate" href="https://varlock.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/393"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Use @decorator comments in your .env file(s) to create a declarative schema for your config and a new function call syntax to securely load secrets from external sources. 

Varlock is our tool that uses this parser to actually load your .env files, and then applies the schema that you have defined. It is a CLI, library, and will communicate with a native Mac application that enables using biometric auth to securely encrypt your local secrets.

- [varlock @ GitHub](https://github.com/dmno-dev/varlock).]]>
            </summary>
            <updated>2026-01-20T15:31:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/408</id>
            <title type="text"><![CDATA[SOPS: Secrets OPerationS]]></title>
            <link rel="alternate" href="https://getsops.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/408"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SOPS is an editor of encrypted files that supports YAML, JSON, ENV, INI and BINARY formats and encrypts with AWS KMS, GCP KMS, Azure Key Vault, age, and PGP

- [SOPS @ GitHub](https://github.com/getsops/sops).

Related contents:

- [pre-commit-hook-ensure-sops @ GitHub](https://github.com/yuvipanda/pre-commit-hook-ensure-sops).
- [Managing Kubernetes Secrets with Mozilla SOPS and AGE @ Cyril Baah&amp;#039;s Medium](https://medium.com/@cbaah123/managing-kubernetes-secrets-with-mozilla-sops-and-age-780c84e6ec5e).]]>
            </summary>
            <updated>2026-03-06T07:15:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/440</id>
            <title type="text"><![CDATA[Force Push Secret Scanner]]></title>
            <link rel="alternate" href="https://github.com/trufflesecurity/force-push-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/440"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scan for secrets in dangling commits on GitHub using GH Archive data. 

This tool scans for secrets in dangling (dereferenced) commits on GitHub created by force push events. A force push occurs when developers overwrite commit history, which often contains mistakes, like hard-coded credentials. This project relies on archived force push event data in the GHArchive to identify the relevant commits.

Related contents:

- [Guest Post: How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets @ Truffle Security](https://trufflesecurity.com/blog/guest-post-how-i-scanned-all-of-github-s-oops-commits-for-leaked-secrets).
- [Comment un hacker a scanné tous les commits &amp;quot;oops&amp;quot; de GitHub et trouvé 25k$ de secrets @ Korben :fr:](https://korben.info/hacker-scanne-tous-commits-oops-github.html).]]>
            </summary>
            <updated>2025-08-28T17:10:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/464</id>
            <title type="text"><![CDATA[kubechecks]]></title>
            <link rel="alternate" href="https://kubechecks.readthedocs.io/en/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/464"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fearless Kubernetes App Updates.
Check your Kubernetes manifests before it hits the cluster.

kubechecks allows users of Github and Gitlab to see exactly what their changes will affect on their current ArgoCD deployments, as well as automatically run various conformance test suites prior to merge.

- [kubechecks @ GitHub](https://github.com/zapier/kubechecks).]]>
            </summary>
            <updated>2025-08-28T17:14:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/475</id>
            <title type="text"><![CDATA[Kingfisher]]></title>
            <link rel="alternate" href="https://github.com/mongodb/kingfisher" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/475"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Kingfisher is a blazingly fast secret‑scanning and validation tool built in Rust. It combines Intel’s hardware‑accelerated Hyperscan regex engine with language‑aware parsing via Tree‑Sitter, and ships with hundreds of built‑in rules to detect, validate, and triage secrets before they ever reach production.

Related contents:

- [MongoDB Launches an Open Source Real-Time Secret Scanner @ It&amp;#039;s FOSS News](https://news.itsfoss.com/mongodb-launches-kingfisher/).]]>
            </summary>
            <updated>2025-09-29T05:52:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/590</id>
            <title type="text"><![CDATA[zizmor]]></title>
            <link rel="alternate" href="https://zizmor.sh/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/590"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[zizmor is a static analysis tool for GitHub Actions. It can find many common security issues in typical GitHub Actions CI/CD setups.

- [zizmor @ GitHub](https://github.com/zizmorcore/zizmor).

Related contents:

- [How to Harden GitHub Actions: The Unofficial Guide @ Wiz](https://www.wiz.io/blog/github-actions-security-guide).
- [How to detect vulnerable GitHub Actions at scale with Zizmor @ Grafana Labs Blog](https://grafana.com/blog/2025/06/26/how-to-detect-vulnerable-github-actions-at-scale-with-zizmor/).
- [Améliorer la maintenance de vos workflows GitHub @ JoliCode :fr:](https://jolicode.com/blog/ameliorer-la-maintenance-de-vos-workflows-github).]]>
            </summary>
            <updated>2026-06-09T12:17:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/764</id>
            <title type="text"><![CDATA[Pipask]]></title>
            <link rel="alternate" href="https://github.com/feynmanix/pipask" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/764"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Safer python package installs with audit and consent 𝘣𝘦𝘧𝘰𝘳𝘦 install.

Pipask is a drop-in replacement for pip that performs security checks before installing a package. Unlike pip, which needs to download and execute code from source distribution first to get dependency metadata, pipask relies on metadata from PyPI whenever possible. If 3rd party code execution is necessary, pipask asks for consent first. The actual installation is handed over to pip if installation is approved.]]>
            </summary>
            <updated>2025-08-28T18:06:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/935</id>
            <title type="text"><![CDATA[Teller]]></title>
            <link rel="alternate" href="https://github.com/tellerops/teller" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/935"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Cloud native secrets management for developers - never leave your command line for secrets. 

Never leave your terminal to use secrets while developing, testing, and building your apps.

Instead of custom scripts, tokens in your .zshrc files, visible EXPORTs in your bash history, misplaced .env.production files and more around your workstation -- just use teller and connect it to any vault, key store, or cloud service you like (Teller support Hashicorp Vault, AWS Secrets Manager, Google Secret Manager, and many more).]]>
            </summary>
            <updated>2025-08-28T18:34:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1002</id>
            <title type="text"><![CDATA[Fix Inventory by Some Engineering Inc.]]></title>
            <link rel="alternate" href="https://fixinventory.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1002"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fix Inventory is an open-source cloud asset inventory tool for infrastructure and security engineers.

Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes. 

Fix Inventory enables a broad set of exploration and automation scenarios. Its foundation is a graph-based data model, which exposes resource metadata and dependency relationships between your service&amp;#039;s assets.

A powerful CLI allows you to search, explore, and manage your cloud resources.

- [Fix Inventory](https://github.com/someengineering/fixinventory).

Related contents:

- [Fix Inventory - L&amp;#039;alternative open source aux scanners de sécurité cloud à 100 000 boules l&amp;#039;année @ Korben :fr:](https://korben.info/fix-inventory-scanner-securite-cloud-open-source.html).]]>
            </summary>
            <updated>2025-08-28T18:44:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1028</id>
            <title type="text"><![CDATA[The Update Framework (TUF)]]></title>
            <link rel="alternate" href="https://theupdateframework.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1028"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A framework for securing software update systems.

The Update Framework (TUF) maintains the security of software update systems, providing protection even against attackers that compromise the repository or signing keys. TUF provides a flexible framework and specification that developers can adopt into any software update system.

- [The Update Framework specification @ GitHub](https://github.com/theupdateframework/specification).
- [python-tuf @ GitHub](https://github.com/theupdateframework/python-tuf).

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).
- [Secure publication of Datadog Agent integrations with TUF and in-toto @ Datadog](https://www.datadoghq.com/blog/engineering/secure-publication-of-datadog-agent-integrations-with-tuf-and-in-toto/).]]>
            </summary>
            <updated>2025-08-28T18:48:41+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1034</id>
            <title type="text"><![CDATA[GuardDog]]></title>
            <link rel="alternate" href="https://github.com/DataDog/guarddog" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1034"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages.

GuardDog is a CLI tool that allows to identify malicious PyPI and npm packages or Go modules. It runs a set of heuristics on the package source code (through Semgrep rules) and on the package metadata.
GuardDog can be used to scan local or remote PyPI and npm packages or Go modules using any of the available heuristics.

Related contents:

- [Finding malicious PyPI packages through static code analysis: Meet GuardDog @ Datadog Security Labs](https://securitylabs.datadoghq.com/articles/guarddog-identify-malicious-pypi-packages/).
- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-28T18:50:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1477</id>
            <title type="text"><![CDATA[External Secrets Operator]]></title>
            <link rel="alternate" href="https://external-secrets.io/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1477"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[External Secrets Operator reads information from a third-party service like AWS Secrets Manager and automatically injects the values as Kubernetes Secrets. 

- [External Secrets Operator @ GitHub](https://github.com/external-secrets/external-secrets).

Related contents:

- [(Almost) Every infrastructure decision I endorse or regret after 4 years running infrastructure at a startup @ Jack&amp;#039;s home on the web](https://cep.dev/posts/every-infrastructure-decision-i-endorse-or-regret-after-4-years-running-infrastructure-at-a-startup/).
- [How Maintainer Burnout Is Causing a Kubernetes Security Disaster @ The New Stack](https://thenewstack.io/how-maintainer-burnout-is-causing-a-kubernetes-security-disaster/).
- [GitOps architecture, patterns and anti-patterns @ Platform Engineering](https://platformengineering.org/blog/gitops-architecture-patterns-and-anti-patterns).
- [Discover the External Secret Operator (ESO) OVHcloud Provider to manage your Kubernetes secrets 🎉 @ OVHcloud](https://blog.ovhcloud.com/discover-the-external-secret-operator-eso-ovhcloud-provider-to-manage-your-kubernetes-secrets-%f0%9f%8e%89/).]]>
            </summary>
            <updated>2026-04-14T08:11:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1523</id>
            <title type="text"><![CDATA[Gixy]]></title>
            <link rel="alternate" href="https://gixy.getpagespeed.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1523"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[NGINX configuration static analyzer.

Gixy is a tool to analyze Nginx configuration. The main goal of Gixy is to prevent security misconfiguration and automate flaw detection.

- [Gixy @ GitHub](https://github.com/dvershinin/gixy).]]>
            </summary>
            <updated>2025-08-28T20:11:23+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1618</id>
            <title type="text"><![CDATA[Novops]]></title>
            <link rel="alternate" href="https://novops.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1618"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Cross-platform secret &amp;amp; config manager for development and CI environments 

Novops, the universal secret and configuration manager for development, applications and CI.

- [Novops @ GitHub](https://github.com/PierreBeucher/novops).

Related contents:

- [Novops facilite l&amp;#039;accès aux secrets @ DevSecOps :fr:](https://blog.stephane-robert.info/post/novops-secrets/).]]>
            </summary>
            <updated>2025-08-28T20:25:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1886</id>
            <title type="text"><![CDATA[🔍 LFIer]]></title>
            <link rel="alternate" href="https://github.com/Cybersecurity-Ethical-Hacker/lfier" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1886"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🔍 LFIer is a powerful and efficient tool for detecting Local File Inclusion (LFI) vulnerabilities in web applications. 

🔍 LFIer is a tool engineered to detect Local File Inclusion (LFI) vulnerabilities in web applications. It scans URLs with parameters, injects various payloads, and checks for indicators in the responses to identify potential LFI vulnerabilities. Leveraging asynchronous programming, LFIer ensures efficient and accurate scanning, even in environments protected by WAFs or cloud-based defenses.

Related contents:

- [ 🚀 𝗟𝗙𝗜𝗲𝗿 : L’outil INDISPENSABLE pour détecter les failles LFI ! @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_cybersaezcuritaez-pentest-lfier-activity-7287034791554633728-dELj/).]]>
            </summary>
            <updated>2025-08-28T21:12:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2293</id>
            <title type="text"><![CDATA[Mobile Security Framework (MobSF)]]></title>
            <link rel="alternate" href="https://mobsf.github.io/docs/#/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2293"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. 

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. MobSF can be used for a variety of use cases such as mobile application security, penetration testing, malware analysis, and privacy analysis. The Static Analyzer supports popular mobile app binaries like APK, IPA, APPX and source code. Meanwhile, the Dynamic Analyzer supports both Android and iOS applications and offers a platform for interactive instrumented testing, runtime data and network traffic analysis. MobSF seamlessly integrates with your DevSecOps or CI/CD pipeline, facilitated by REST APIs and CLI tools, enhancing your security workflow with ease.

- [Mobile Security Framework (MobSF) @ GitHub](https://github.com/MobSF/Mobile-Security-Framework-MobSF).]]>
            </summary>
            <updated>2025-08-28T22:18:40+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2450</id>
            <title type="text"><![CDATA[picklescan]]></title>
            <link rel="alternate" href="https://github.com/mmaitre314/picklescan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2450"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security scanner detecting Python Pickle files performing suspicious actions]]>
            </summary>
            <updated>2025-08-28T22:45:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2639</id>
            <title type="text"><![CDATA[Am I Isolated]]></title>
            <link rel="alternate" href="https://github.com/edera-dev/am-i-isolated" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2639"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Validate the isolation posture of your container environment.

Am I Isolated is a security posture benchmarking tool.

It evaluates a given runtime environment and attempts to look for things which may be a security problem, as well as providing suggestions for solving the security problem.]]>
            </summary>
            <updated>2025-08-28T23:17:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2656</id>
            <title type="text"><![CDATA[DefectDojo]]></title>
            <link rel="alternate" href="https://www.defectdojo.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2656"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source DevSecOps.  CI/CD and DevSecOps Automation

The leading application vulnerability management tool.
Built for both DevSecOps and traditional application security.
 DevSecOps, ASPM, Vulnerability Management. All on one platform. 

DefectDojo is a DevSecOps, ASPM (application security posture management), and vulnerability management tool. DefectDojo orchestrates end-to-end security testing, vulnerability tracking, deduplication, remediation, and reporting.

- [DefectDojo @ GitHub](https://github.com/DefectDojo/django-DefectDojo).

Source: [Savez-vous ce qui est un OpenVOC ? @ Florian Dudaev&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/cyberflood_soc-voc-vulnerability-activity-7274743353609445377-8WOr/).]]>
            </summary>
            <updated>2025-08-28T23:19:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2660</id>
            <title type="text"><![CDATA[Artifactory]]></title>
            <link rel="alternate" href="https://jfrog.com/artifactory/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2660"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Universal Artifact Repository Manager.

Definitive artifact management for flexible development and trusted delivery at any scale.

 JFrog Artifactory is the single solution for housing and managing all the artifacts, binaries, packages, files, containers, and components for use throughout your software supply chain.
JFrog Artifactory serves as your central hub for DevOps, integrating with your tools and processes to improve automation, increase integrity, and incorporate best practices along the way. 

- [Anatomie d&amp;#039;une faille @ GDG France&amp;#039;s YouTube :fr:](https://www.youtube.com/watch?v=ccnSpR-CSHA).]]>
            </summary>
            <updated>2025-08-28T23:21:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2662</id>
            <title type="text"><![CDATA[Docker Scout]]></title>
            <link rel="alternate" href="https://docs.docker.com/scout/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2662"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Docker Scout is a solution for proactively enhancing your software supply chain security. By analyzing your images, Docker Scout compiles an inventory of components, also known as a Software Bill of Materials (SBOM). The SBOM is matched against a continuously updated vulnerability database to pinpoint security weaknesses.

- [Enhancing Container Security with Docker Scout and Secure Repositories @ Docker blog ](https://www.docker.com/blog/enhancing-container-security-with-docker-scout-and-secure-repositories/).]]>
            </summary>
            <updated>2025-08-28T23:21:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2707</id>
            <title type="text"><![CDATA[Squealer]]></title>
            <link rel="alternate" href="https://github.com/owenrumney/squealer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2707"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Telling tales on you for leaking secrets!.

Squealer scans a git repository or filesystem for secrets that are being leaked deep within the commit history.]]>
            </summary>
            <updated>2025-08-28T23:27:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2768</id>
            <title type="text"><![CDATA[Talisman]]></title>
            <link rel="alternate" href="https://thoughtworks.github.io/talisman/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2768"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Using a pre-commit hook, Talisman validates the outgoing changeset for things that look suspicious — such as tokens, passwords, and private keys. 

Talisman is a tool that scans git changesets to ensure that potential secrets or sensitive information do not leave the developer&amp;#039;s workstation.
It validates the outgoing changeset for things that look suspicious - such as potential SSH keys, authorization tokens, private keys etc.

- [Talisman @ GitHub](https://github.com/thoughtworks/talisman).]]>
            </summary>
            <updated>2025-08-28T23:37:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2780</id>
            <title type="text"><![CDATA[Awesome DevSecOps]]></title>
            <link rel="alternate" href="https://github.com/devsecops/awesome-devsecops" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2780"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Inspired by the awesome-* trend on GitHub. This is a collection of documents, presentations, videos, training materials, tools, services and general leadership that support the DevSecOps mission. These are the essential building blocks and tidbits that can help you to arrange for a DevSecOps experiment or to help you build out your own DevSecOps program.]]>
            </summary>
            <updated>2025-08-28T23:39:23+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2870</id>
            <title type="text"><![CDATA[Policy Sentry]]></title>
            <link rel="alternate" href="https://policy-sentry.readthedocs.io/en/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2870"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[IAM Least Privilege Policy Generator.

Policy Sentry is an AWS IAM Least Privilege Policy Generator, auditor, and analysis database. It compiles database tables based on the AWS IAM Documentation on Actions, Resources, and Condition Keys and leverages that data to create least-privilege IAM policies.

- [Policy Sentry @ GitHub](https://github.com/salesforce/policy_sentry).]]>
            </summary>
            <updated>2025-08-28T23:54:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2920</id>
            <title type="text"><![CDATA[sastsweep]]></title>
            <link rel="alternate" href="https://github.com/chebuya/sastsweep" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2920"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automatically detect potential vulnerabilities and analyze repository metrics to prioritize open source security research targets .

sastsweep is a tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such as popularity and project size, enabling targeted vulnerability research. It automatically detects potential vulnerabilities using semgrep and provides a streamlined HTML report, allowing researchers to quickly drill down to the affected portion of the codebase.]]>
            </summary>
            <updated>2025-08-29T00:02:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2928</id>
            <title type="text"><![CDATA[TrailScraper]]></title>
            <link rel="alternate" href="https://github.com/flosell/trailscraper" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2928"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A command-line tool to get valuable information out of AWS CloudTrail and a general purpose toolbox for working with IAM policies]]>
            </summary>
            <updated>2025-08-29T00:06:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2929</id>
            <title type="text"><![CDATA[Cloud Custodian]]></title>
            <link rel="alternate" href="https://cloudcustodian.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2929"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources.

Cloud Custodian enables you to manage your cloud resources by filtering, tagging, and then applying actions to them. The YAML DSL allows defininition of rules to enable well-managed cloud infrastructure that&amp;#039;s both secure and cost optimized. 

Cloud Custodian, also known as c7n, is a rules engine for managing public cloud accounts and resources. It allows users to define policies to enable a well managed cloud infrastructure, that&amp;#039;s both secure and cost optimized. It consolidates many of the adhoc scripts organizations have into a lightweight and flexible tool, with unified metrics and reporting.

- [Cloud Custodian @ GitHub](https://github.com/cloud-custodian/cloud-custodian/).]]>
            </summary>
            <updated>2025-08-29T00:06:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2933</id>
            <title type="text"><![CDATA[detect-secrets]]></title>
            <link rel="alternate" href="https://github.com/Yelp/detect-secrets" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2933"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An enterprise friendly way of detecting and preventing secrets in code. 

detect-secrets is an aptly named module for (surprise, surprise) detecting secrets within a code base.]]>
            </summary>
            <updated>2026-07-01T15:03:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2934</id>
            <title type="text"><![CDATA[GitGuardian]]></title>
            <link rel="alternate" href="https://www.gitguardian.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2934"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Git Security Scanning &amp;amp; Secrets Detection.

- [ggshield @ GitHub](https://github.com/GitGuardian/ggshield).
- [Doctolib divise par deux ses incidents de sécurité liés aux secrets@ LeMagIT :fr:](https://www.lemagit.fr/etude/Doctolib-divise-par-deux-ses-incidents-de-securite-lies-aux-secrets).]]>
            </summary>
            <updated>2025-08-29T00:06:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3123</id>
            <title type="text"><![CDATA[Doppler]]></title>
            <link rel="alternate" href="https://www.doppler.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3123"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Centralized Cloud-Based Secrets Management Platform.

Securely manage, orchestrate, and govern secrets at scale with Doppler’s developer-first cloud hosted platform.

- [Doppler CLI @ GitHub](https://github.com/DopplerHQ/cli).

Related contents:

- [10 CLI apps that have actually improved the way I work in the terminal @ Dreams of Code&amp;#039;s YouTube](https://www.youtube.com/watch?v=EJ6uvqhKR4M).]]>
            </summary>
            <updated>2025-09-22T06:14:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3134</id>
            <title type="text"><![CDATA[vulncov]]></title>
            <link rel="alternate" href="https://github.com/mllamazares/vulncov/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3134"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.

vulncov correlates Semgrep scans with Python test code coverage to identify which vulnerable code has been executed by unit tests, helping prioritize SAST findings and reduce false positives. It also leverages a self-hosted LLM to suggest bug fixes!]]>
            </summary>
            <updated>2025-08-29T00:38:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3162</id>
            <title type="text"><![CDATA[Node Version Audit]]></title>
            <link rel="alternate" href="https://www.github.developerdan.com/node-version-audit/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3162"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Node Version Audit is a convenience tool to easily check a given Node.js version against a regularly updated list of CVE exploits, new releases, and end of life dates.

Node Version Audit is not: exploit detection/mitigation, vendor-specific version tracking, a replacement for staying informed on Node.js releases and security exploits. 

- [Node Version Audit @ GitHub](https://github.com/lightswitch05/node-version-audit).]]>
            </summary>
            <updated>2025-08-29T00:44:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3163</id>
            <title type="text"><![CDATA[s3cme]]></title>
            <link rel="alternate" href="https://github.com/mchmarny/s3cme" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3163"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sample Go app repo with test and release pipelines optimized for software supply chain security (S3C).

 Template Go app repo with local test/lint/build/vulnerability check workflow, and on tag image test/build/release pipelines, with ko generative SBOM, cosign attestation, and SLSA build provenance]]>
            </summary>
            <updated>2025-08-29T00:44:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3222</id>
            <title type="text"><![CDATA[Cosign]]></title>
            <link rel="alternate" href="https://github.com/sigstore/cosign" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3222"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Code signing and transparency for containers and binaries.
Signing OCI containers (and other artifacts) using Sigstore!
Cosign aims to make signatures invisible infrastructure.

Related contents:

- [Sécuriser la Supply Chain avec Cosign @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/supply-chain/cosign/).
- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).]]>
            </summary>
            <updated>2025-08-29T00:53:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3236</id>
            <title type="text"><![CDATA[Gato]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/gato" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3236"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Gato, or GitHub Attack Toolkit, is an enumeration and attack tool that allows both blue teamers and offensive security practitioners to identify and exploit pipeline vulnerabilities within a GitHub organization&amp;#039;s public and private repositories.]]>
            </summary>
            <updated>2025-08-29T00:56:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3266</id>
            <title type="text"><![CDATA[Dependency-Track]]></title>
            <link rel="alternate" href="https://dependencytrack.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3266"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Software Bill of Materials (SBOM) Analysis.

- [Dependency-Track @ GitHub](https://github.com/DependencyTrack/dependency-track).
- [Démarrer avec Dependency Track @ Culture et Outils DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/analyser-code/dependency-track/).]]>
            </summary>
            <updated>2025-08-29T01:00:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3287</id>
            <title type="text"><![CDATA[sbomqs]]></title>
            <link rel="alternate" href="https://github.com/interlynk-io/sbomqs" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3287"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SBOM quality score - Quality metrics for your sboms.
sbomqs is your primary tool to assess an SBOM&amp;#039;s quality and compliance. The higher the score the more consumable &amp;amp; compliant your SBOMs are.]]>
            </summary>
            <updated>2025-08-29T01:04:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3317</id>
            <title type="text"><![CDATA[Octoscan]]></title>
            <link rel="alternate" href="https://github.com/synacktiv/octoscan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3317"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Octoscan is a static vulnerability scanner for GitHub action workflows. 

- [action octoscan @ GitHub](https://github.com/synacktiv/action-octoscan).]]>
            </summary>
            <updated>2025-08-29T01:09:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3343</id>
            <title type="text"><![CDATA[Venator]]></title>
            <link rel="alternate" href="https://github.com/nianticlabs/venator" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3343"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A flexible detection platform that simplifies rule management and deployment with K8s CronJob and Helm. Venator is flexible enough to run standalone or with other job schedulers like Nomad.

Venator is optimized for Kubernetes deployment but is flexible enough to run standalone or with other job schedulers like Nomad. It provides a highly adaptable detection engine that prioritizes simplicity, extensibility, and ease of maintenance. Supporting multiple query engines and publishers, Venator allows you to easily switch between different data lakes or services with minimal changes, avoiding vendor lock-in and dependence on specific SIEM solutions for signal generation.]]>
            </summary>
            <updated>2025-08-29T01:13:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3392</id>
            <title type="text"><![CDATA[FOSSA]]></title>
            <link rel="alternate" href="https://fossa.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3392"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Comprehensive Open Source Security and SBOM Management. Secure Your Products From Repo to Release.

Stop vulnerabilities, automate compliance, and mitigate third-party risk in your applications.

- [FOSSA CLI @ GitHub](https://github.com/fossas/fossa-cli).]]>
            </summary>
            <updated>2025-08-29T01:21:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3464</id>
            <title type="text"><![CDATA[ArcherySec]]></title>
            <link rel="alternate" href="https://www.archerysec.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3464"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OPEN SOURCE ORCHESTRATION AND CORRELATION TOOL.  ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec. 

Automate Your Application Security Orchestration And Correlation (ASOC) Using ArcherySec.

ArcherySec allow to interact with continuous integration/continuous delivery (CI/CD) toolchains to specify testing, and control the release of a given build based on results. Its include prioritization functions, enabling you to focus on the most critical vulnerabilities. ArcherySec uses popular open source tools to perform comprehensive scanning for web application and network. The developers can also utilize the tool for implementation of their DevOps CI/CD environment.

- [ArcherySec @ GitHub](https://github.com/archerysec/archerysec).
- [🚨 ArcherySec - La plateforme open source incontournable pour l&amp;#039;orchestration de la sécurité des applications 🛡️ @ Souleiman S.&amp;#039; LinkedIn :fr:](https://www.linkedin.com/posts/souleiman-s-497469156_cybersaezcuritaez-opensource-vulnaezrabilitaezs-activity-7244677201982369792-792I/).]]>
            </summary>
            <updated>2025-08-29T01:34:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3618</id>
            <title type="text"><![CDATA[Sigstore]]></title>
            <link rel="alternate" href="https://www.sigstore.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3618"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sigstore is an open source project for improving software supply chain security. The Sigstore framework and tooling empowers software developers and consumers to securely sign and verify software artifacts such as release files, container images, binaries, software bills of materials (SBOMs), and more. Signatures are generated with ephemeral signing keys so there’s no need to manage keys. Signing events are recorded in a tamper-resistant public log so software developers can audit signing events.

- [Sigstore @ GitHub](https://github.com/sigstore/sigstore).
- [Sigstore documentation](https://docs.sigstore.dev/).

Related contents:

- [Streamline security with keyless signing and verification in GitLab @ GitLab](https://about.gitlab.com/blog/2023/09/13/keyless-signing-with-cosign/).
- [Annotate container images with build provenance using Cosign in GitLab CI/CD @ GitLab](https://about.gitlab.com/blog/2024/09/04/annotate-container-images-with-build-provenance-using-cosign-in-gitlab-ci-cd/).
- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).
- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).]]>
            </summary>
            <updated>2026-02-18T13:13:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3870</id>
            <title type="text"><![CDATA[TruffleHog]]></title>
            <link rel="alternate" href="https://trufflesecurity.com/trufflehog" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3870"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Find and verify secrets. Find leaked credentials.

TruffleHog is the most powerful secrets Discovery, Classification, Validation, and Analysis tool. In this context secret refers to a credential a machine uses to authenticate itself to another machine. This includes API keys, database passwords, private encryption keys, and more...

- [TruffleHog @ GitHub](https://github.com/trufflesecurity/trufflehog).

Related contents:

- [Keeping Secrets Out of Logs @ allan.reyes.sh](https://allan.reyes.sh/posts/keeping-secrets-out-of-logs/).
- [How Security Tool Misuse Is Reshaping Cloud Compromise @ Qualys](https://blog.qualys.com/qualys-insights/2026/02/19/how-security-tool-misuse-is-reshaping-cloud-compromise).]]>
            </summary>
            <updated>2026-03-05T12:17:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3980</id>
            <title type="text"><![CDATA[Ansible Collection - devsec.hardening]]></title>
            <link rel="alternate" href="https://github.com/dev-sec/ansible-collection-hardening" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3980"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL]]>
            </summary>
            <updated>2025-08-29T02:59:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4043</id>
            <title type="text"><![CDATA[OWASP Dependency-Check]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-dependency-check/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4043"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Dependency-Check is a Software Composition Analysis (SCA) tool that attempts to detect publicly disclosed vulnerabilities contained within a project’s dependencies. It does this by determining if there is a Common Platform Enumeration (CPE) identifier for a given dependency. If found, it will generate a report linking to the associated CVE entries.

- [Dependency-Check @ GitHub](https://github.com/dependency-check/DependencyCheck).]]>
            </summary>
            <updated>2025-08-29T03:10:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4119</id>
            <title type="text"><![CDATA[Gitleaks]]></title>
            <link rel="alternate" href="https://gitleaks.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4119"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Gitleaks is a fast, light-weight, portable, and open-source secret scanner for git repositories, files, and directories. 

- [Gitleaks @ GitHub](https://github.com/gitleaks/gitleaks).

Related contents:

- [Gitleaks : Evitez le vol de secrets sur Git ! @ Geeek.org :fr:](https://www.geeek.org/securiser-depots-git-gitleaks/).
- [I&amp;#039;m Switching to Python and Actually Liking It @ César Soto Valero](https://www.cesarsotovalero.net/blog/i-am-switching-to-python-and-actually-liking-it.html).]]>
            </summary>
            <updated>2025-08-29T03:23:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4652</id>
            <title type="text"><![CDATA[OWASP dep-scan]]></title>
            <link rel="alternate" href="https://github.com/owasp-dep-scan/dep-scan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4652"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration with ASPM/VM platforms and in CI environments.]]>
            </summary>
            <updated>2025-08-29T04:51:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4684</id>
            <title type="text"><![CDATA[OpenBao]]></title>
            <link rel="alternate" href="https://openbao.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4684"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

- [OpenBao @ GitHub](https://github.com/openbao/openbao).

Related contents:

- [OpenBao (Hashicorp Vault Fork effort) FAQ @ LF Edge](https://wiki.lfedge.org/display/OH/OpenBao+%28Hashicorp+Vault+Fork+effort%29+FAQ).
- [Open source forkers stick an OpenBao in the oven @ The Register](https://www.theregister.com/2023/12/08/hashicorp_openbao_fork/).
- [Vault on Kubernetes using OpenBao @ nanibot.net](https://nanibot.net/posts/vault/).
- [Vault SSH : accès sécurisé aux serveurs @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/secrets/hashicorp-vault/ssh-secrets/).
- [Monitor HCP Vault Dedicated Audit Logs with SigNoz @ SigNoz](https://signoz.io/docs/integrations/outposts/hcp-vault/).]]>
            </summary>
            <updated>2026-07-06T11:36:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4769</id>
            <title type="text"><![CDATA[SOPS]]></title>
            <link rel="alternate" href="https://github.com/getsops/sops" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4769"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Simple and flexible tool for managing secrets.

SOPS is an editor of encrypted files that supports YAML, JSON, ENV, INI and BINARY formats and encrypts with AWS KMS, GCP KMS, Azure Key Vault, age, and PGP.

- [ SOPS la solution de gestion de secret DevOps ? @ DamyR :fr:](https://www.damyr.fr/posts/sops/).]]>
            </summary>
            <updated>2025-08-29T05:11:57+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4843</id>
            <title type="text"><![CDATA[Chalk]]></title>
            <link rel="alternate" href="https://github.com/crashappsec/chalk" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4843"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Total visibility of your software engineering lifecycle.

Chalk™ captures metadata at build time, and can add a small &amp;#039;chalk mark&amp;#039; (metadata) to any artifacts, so they can be identified in production. Chalk can also extract chalk marks and collect additional metadata about the operating environment when it does this.

Using Chalk, you can build a graph connecting development and production, so that devops engineers understand what is happening in the development process, and so that developers can understand what is happening in the infrastructure. With this information they can work better together.

- [Chalk: Open-source software security and infrastructure visibility tool @ Help Net Security](https://www.helpnetsecurity.com/2023/10/03/chalk-open-source-software-security-tool/).]]>
            </summary>
            <updated>2025-08-29T05:24:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4899</id>
            <title type="text"><![CDATA[Kubescape]]></title>
            <link rel="alternate" href="https://kubescape.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4899"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters.

Kubescape is an open-source Kubernetes security platform. It includes risk analysis, security compliance, and misconfiguration scanning. Targeted at the DevSecOps practitioner or platform engineer, it offers an easy-to-use CLI interface, flexible output formats, and automated scanning capabilities. It saves Kubernetes users and admins precious time, effort, and resources.

- [Kubescape @ GitHub](https://github.com/kubescape/kubescape).
- [Sécuriser Kubernetes avec Kubescape @ Culture et Outils DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/conteneurs/kubescape/).]]>
            </summary>
            <updated>2025-08-29T05:33:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6292</id>
            <title type="text"><![CDATA[OSV]]></title>
            <link rel="alternate" href="https://osv.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6292"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A distributed vulnerability database for Open Source.
An open, precise, and distributed approach to producing and consuming vulnerability information for open source. 

- [OSV @ GitHub](https://github.com/google/osv.dev).
- [OSV-Scanner @ GitHub](https://github.com/google/osv-scanner/).

Related contents:

- [Episode \#497: sécurisation de la chaîne d’approvisionnement logicielle (software supply chain) @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/).
- [Episode \#499 consacré aux référentiels de vulnérabilités @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/referentiels-de-vulnerabilites/).
- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).]]>
            </summary>
            <updated>2026-02-18T13:12:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6939</id>
            <title type="text"><![CDATA[Vault by HashiCorp]]></title>
            <link rel="alternate" href="https://www.vaultproject.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6939"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Manage Secrets &amp;amp; Protect Sensitive Data

Secure, store and tightly control access to tokens, passwords, certificates, encryption keys for protecting secrets and other sensitive data using a UI, CLI, or HTTP API.

- [Vault @ GitHub](https://github.com/hashicorp/vault).

Related contents:

- [How To Centralize Kubernetes Secrets Management With Vault @ The New Stack](https://thenewstack.io/how-to-centralize-kubernetes-secrets-management-with-vault/).
- [From key sprawl to scalable control: Rethinking SSH access @ Hashicorp&amp;#039;s The Stack](https://www.hashicorp.com/en/blog/from-key-sprawl-to-scalable-control-rethinking-ssh-access).]]>
            </summary>
            <updated>2025-10-15T12:28:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7661</id>
            <title type="text"><![CDATA[OpenSCAP]]></title>
            <link rel="alternate" href="https://www.open-scap.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7661"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[NIST Certified SCAP 1.2 toolkit. The oscap program is a command line tool that allows users to load, scan, validate, edit, and export SCAP documents.

The OpenSCAP ecosystem provides multiple tools to assist administrators and auditors with assessment, measurement and enforcement of security baselines. We maintain great flexibility and interoperability, reducing costs of performing security audits.

- [OpenSCAP @ GitHub](https://github.com/OpenSCAP/openscap).

Related contents:

- [Auditez la sécurité de vos serveurs avec OpenScap @ Culture et Outils DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/durcissement/openscap/).]]>
            </summary>
            <updated>2025-12-03T09:23:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7964</id>
            <title type="text"><![CDATA[Vault by HashiCorp]]></title>
            <link rel="alternate" href="https://developer.hashicorp.com/vault" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7964"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Vault handles leasing, key revocation, key rolling, and auditing. Vault presents a unified API to access multiple backends: HSMs, AWS IAM, SQL databases, raw key/value, and more.

- [HashiCorp Vault @ GitHub](https://github.com/hashicorp/vault).

Related contents:

- [Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault @ Cyata](https://cyata.ai/blog/cracking-the-vault-how-we-found-zero-day-flaws-in-authentication-identity-and-authorization-in-hashicorp-vault/).
- [No More Hardcoded Secrets: Automatic Database Credential Rotation with Vault, AKS and Postgres🔐 @ Poojan Mehta](https://dev.to/poojan18/no-more-hardcoded-secrets-automatic-database-credential-rotation-with-vault-aks-and-postgres-1nmn).]]>
            </summary>
            <updated>2025-09-15T13:26:40+00:00</updated>
        </entry>
    </feed>
