{"id":66175,"url":"https://github.com/noobpk/mlsecops-devsecops-awesome","name":"mlsecops-devsecops-awesome","description":"A repository for MLSecOps and DevSecOps research and more!","projects_count":37,"last_synced_at":"2026-07-19T22:00:23.067Z","repository":{"id":244971762,"uuid":"816871300","full_name":"noobpk/MLSecOps-DevSecOps-Awesome","owner":"noobpk","description":"A repository for MLSecOps and DevSecOps research and more!","archived":false,"fork":false,"pushed_at":"2026-02-20T10:00:51.000Z","size":178,"stargazers_count":21,"open_issues_count":4,"forks_count":5,"subscribers_count":2,"default_branch":"main","last_synced_at":"2026-06-14T00:02:23.830Z","etag":null,"topics":["awesome","awesome-list","devops","devsecops","jenkins-pipeline","mlops","mlsecops"],"latest_commit_sha":null,"homepage":"","language":"Groovy","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/noobpk.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2024-06-18T14:57:33.000Z","updated_at":"2026-04-26T19:47:37.000Z","dependencies_parsed_at":"2026-03-12T01:00:40.334Z","dependency_job_id":null,"html_url":"https://github.com/noobpk/MLSecOps-DevSecOps-Awesome","commit_stats":{"total_commits":56,"total_committers":2,"mean_commits":28.0,"dds":0.5,"last_synced_commit":"9550ee123f4d311c3261f608cca7c4df85c03be1"},"previous_names":["noobpk/mlops-awesome"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/noobpk/MLSecOps-DevSecOps-Awesome","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/noobpk%2FMLSecOps-DevSecOps-Awesome","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/noobpk%2FMLSecOps-DevSecOps-Awesome/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/noobpk%2FMLSecOps-DevSecOps-Awesome/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/noobpk%2FMLSecOps-DevSecOps-Awesome/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/noobpk","download_url":"https://codeload.github.com/noobpk/MLSecOps-DevSecOps-Awesome/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/noobpk%2FMLSecOps-DevSecOps-Awesome/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34999792,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-01T02:00:05.325Z","response_time":130,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-09-24T15:29:40.292Z","updated_at":"2026-07-19T22:00:23.067Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Best Practices","Resources","Repository Overview","Case Studies","Community"],"sub_categories":["Cousers","💥 MLSecOps Pipeline","💥 DevSecOps Pipeline","Articles","Papers","Tutorials"],"readme":"# MLSecOps - DevSecOps - Awesome\n\nThis project is dedicated to curating a comprehensive list of resources, tools, and best practices at the intersection of Machine Learning Security Operations (MLSecOps), and Development Security Operations (DevSecOps). Our goal is to provide a centralized hub for professionals, researchers, and enthusiasts who are passionate about integrating security into the development and deployment of machine learning systems.\n\n## What is MLSecOps?\n\nMLSecOps is an emerging field that focuses on the secure and efficient operation of machine learning models in production environments. It combines the principles of DevSecOps with the unique challenges of machine learning, emphasizing the importance of security, privacy, and compliance throughout the ML lifecycle.\n\n## What is DevSecOps?\n\nDevSecOps extends the traditional DevOps framework by incorporating security practices into the entire software development process. It aims to automate security checks and integrate them seamlessly into the CI/CD pipeline, ensuring that security is a fundamental part of the development workflow.\n\n## Repository Overview\n\nIn this repository, you will find:\n\n* Resources: Articles, papers, and tutorials on MLSecOps and DevSecOps.\n* Tools: A curated list of open-source tools for securing ML models and development pipelines.\n* Best Practices: Guidelines and methodologies for implementing security measures in ML projects.\n* Case Studies: Real-world examples of successful MLSecOps and DevSecOps implementations.\n* Community: Links to forums, conferences, and groups where you can connect with others interested in these fields.\n\n# Proposed Pipeline\n\n### 💥 MLSecOps Pipeline\n\n![image](https://github.com/user-attachments/assets/44ce27e4-5e41-41cf-ad3e-4a22286c54ef)\n\nArticle anlysis this MLO pipeline 👉 [MLSECOPS: Secure your Large Language Model (LLM) applications](https://lethanhphuc-pk.medium.com/mlsecops-secure-your-large-language-model-llm-applications-6b60cb25c4fa)\n\n### 💥 DevSecOps Pipeline\n\n![image](https://github.com/user-attachments/assets/dabe6315-e05f-4a3d-8c2a-501b9e329c2d)\n\nArticle anlysis this DSO pipeline 👉 [DevSecOps: A journey to protect your applications](https://lethanhphuc-pk.medium.com/devsecops-a-journey-to-protect-your-applications-fdee7b4700eb)\n\n## Resources\n\n### Articles\n\n- [How MLSecOps Can Reshape AI Security](https://www.forbes.com/sites/forbestechcouncil/2023/12/04/how-mlsecops-can-reshape-ai-security/)\n- [MLSecOps Explained: Building Security Into ML \u0026 AI](https://www.brighttalk.com/business/products/custom-webinars-sponsorable-events/originals-episode/SBA56-mlsecops-explained-building-security-into-ml-ai)\n- [The Comprehensive Evolution Of DevSecOps In Modern Software Ecosystems](https://www.forbes.com/sites/forbestechcouncil/2024/03/06/the-comprehensive-evolution-of-devsecops-in-modern-software-ecosystems/)\n- [Deploying a Netflix Clone on EKS Using a DevSecOps Pipeline](https://medium.com/@cloudwithmustafa/deploying-a-netflix-clone-on-eks-using-a-devsecops-pipeline-9ef84d5f952b)\n- [DevSecOps (DevOps) Project: Deploying a Petshop Java-Based Application with CI/CD, Docker, and Kubernetes](https://medium.com/@21harsh12/devsecops-devops-project-deploying-a-petshop-java-based-application-with-ci-cd-docker-and-e737d3a5501b)\n\n### Papers\n\n| Title | Abstract |\n| --- | --- |\n| [Integrating MLSecOps in the Biotechnology Industry 5.0](https://arxiv.org/abs/2402.07967) | Biotechnology Industry 5.0 is advancing with the integration of cutting-edge technologies like Machine Learning (ML), the Internet Of Things (IoT), and cloud computing. It is no surprise that an industry that utilizes data from customers and can alter their lives is a target of a variety of attacks. This chapter provides a perspective of how Machine Learning Security Operations (MLSecOps) can help secure the biotechnology Industry 5.0. The chapter provides an analysis of the threats in the biotechnology Industry 5.0 and how ML algorithms can help secure with industry best practices. This chapter explores the scope of MLSecOps in the biotechnology Industry 5.0, highlighting how crucial it is to comply with current regulatory frameworks. With biotechnology Industry 5.0 developing innovative solutions in healthcare, supply chain management, biomanufacturing, pharmaceuticals sectors, and more, the chapter also discusses the MLSecOps best practices that industry and enterprises should follow while also considering ethical responsibilities. Overall, the chapter provides a discussion of how to integrate MLSecOps into the design, deployment, and regulation of the processes in biotechnology Industry 5.0. |\n| [Security Risks and Best Practices of MLOps: A Multivocal Literature Review](https://ceur-ws.org/Vol-3731/paper13.pdf) | MLOps and tools are designed to streamline the deployment practices and maintenance of production grade ML-enabled systems. As with any software workflow and component, they are susceptible to various security threats. In this paper, we present a Multivocal Literature Review (MLR) aimed at gauging current knowledge of the risks associated with the implementation of MLOps processes and the best practices recommended for their mitigation. By analyzing a varied range of sources of academic papers and non-peer-reviewed technical articles, we synthesize 15 risks and 27 related best practices, which we categorize into 8 themes. We find that while some of the risks are known security threats that can be mitigated through well-established cybersecurity best practices, others represent MLOps-specific risks, mostly related to the management of data and models. |\n| [Backdoor Attacks to Deep Neural Networks: A Survey of the Literature, Challenges, and Future Research Directions](https://ieeexplore.ieee.org/abstract/document/10403914) | Deep neural network (DNN) classifiers are potent instruments that can be used in various security-sensitive applications. Still, they are dangerous to certain attacks that impede or distort their learning process. For example, backdoor attacks involve polluting the DNN learning set with a few samples from one or more source classes, which are then labeled as target classes by an attacker. Even if the DNN is trained on clean samples with no backdoors, this attack will still be successful if a backdoor pattern exists in the training data. Backdoor attacks are difficult to spot and can be used to make the DNN behave maliciously, depending on the target selected by the attacker. In this study, we survey the literature and highlight the latest advances in backdoor attack strategies and defense mechanisms. We finalize the discussion on challenges and open issues, as well as future research opportunities. |\n| [The emergence and importance of DevSecOps: Integrating and reviewing security practices within the DevOps pipeline](https://wjaets.com/content/emergence-and-importance-devsecops-integrating-and-reviewing-security-practices-within) | The emergence of DevSecOps marks a significant paradigm shift in software development, focusing on integrating security practices seamlessly into the DevOps pipeline. This paper explores the evolution, principles, and importance of DevSecOps in contemporary software engineering. DevSecOps arises from the recognition that traditional security measures often lag behind the rapid pace of DevOps development cycles, leading to vulnerabilities and breaches. By integrating security early and continuously throughout the software development lifecycle, DevSecOps aims to proactively identify and mitigate risks without impeding the agility and speed of DevOps practices. This paper delves into the core principles of DevSecOps, emphasizing automation, collaboration, and cultural transformation. Automation streamlines security processes, enabling the automated testing and validation of code for vulnerabilities. Collaboration fosters communication and shared responsibility among developers, operations, and security teams, breaking down silos and promoting a collective approach to security. Cultural transformation involves cultivating a security-first mindset across the organization, where security is not an afterthought but an inherent part of the development process. The importance of DevSecOps cannot be overstated in today's digital landscape, where cyber threats are omnipresent and the cost of security breaches is staggering. By integrating security into every stage of the DevOps pipeline, organizations can enhance their resilience to cyber attacks, comply with regulatory requirements, and build trust with customers.  DevSecOps represents a holistic approach to software development that prioritizes security without compromising speed or innovation. Embracing DevSecOps principles is imperative for organizations seeking to stay ahead in an increasingly complex and hostile digital environment. |\n\n### Tutorials\n\n- [MLSecOps with Automated Online and Offline ML Model Evaluations on Kubernetes](https://www.youtube.com/watch?v=5WUhmWTMo4g\u0026pp=ygURbWxzZWNvcHMgdHV0b3JpYWw%3D)\n- [\"What is MLSecOps?\" Building security into MLOps workflows by leveraging DevSecOps principles.](https://www.youtube.com/watch?v=iwPKQbZumN0\u0026pp=ygURbWxzZWNvcHMgdHV0b3JpYWw%3D)\n- [DevSecOps Tutorial for Beginners | CI Pipeline with GitHub Actions and Docker Scout](https://www.youtube.com/watch?v=gLJdrXPn0ns\u0026pp=ygUSZGV2c2Vjb3BzIHR1dG9yaWFs)\n- [DevSecOps Pipeline Project: Deploy Netflix Clone on Kubernetes](https://www.youtube.com/watch?v=g8X5AoqCJHc\u0026pp=ygUSZGV2c2Vjb3BzIHR1dG9yaWFs)\n- [DevSecOps with Jenkins | Boost Your CICD Pipeline Security !!](https://www.youtube.com/watch?v=QUIXJW_h_K0\u0026pp=ygUSZGV2c2Vjb3BzIHR1dG9yaWFs)\n\n### Cousers\n\n- [Practical DevSecOps](https://www.practical-devsecops.com/)\n- [DevSecOps Training](https://www.eccouncil.org/train-certify/certified-devsecops-engineer-ecde/)\n- [DevSecOps : Master Securing CI/CD | DevOps Pipeline |Handson](https://www.udemy.com/course/devsecops/?utm_source=adwords\u0026utm_medium=udemyads\u0026utm_campaign=Search_DSA_Beta_Prof_la.EN_cc.ROW-English\u0026campaigntype=Search\u0026portfolio=ROW-English\u0026language=EN\u0026product=Course\u0026test=\u0026audience=DSA\u0026topic=\u0026priority=Beta\u0026utm_content=deal4584\u0026utm_term=_._ag_162511579564_._ad_696197165427_._kw__._de_c_._dm__._pl__._ti_dsa-1677053911888_._li_9198559_._pd__._\u0026matchtype=\u0026gad_source=1\u0026gclid=CjwKCAjw74e1BhBnEiwAbqOAjOS1FIYA31Sgo8GjmN7B6Gh5pWR_x1yWCZ0ftdx38RLWVytcJiTdzRoCWtgQAvD_BwE\u0026couponCode=2021PM25)\n\n## Tools\n\n\u003ctable\u003e\n  \u003cthead\u003e\n    \u003ctr\u003e\n      \u003cth\u003ePipeline\u003c/th\u003e\n      \u003cth\u003eStages\u003c/th\u003e\n      \u003cth\u003eTool\u003c/th\u003e\n      \u003cth\u003eDescription\u003c/th\u003e\n    \u003c/tr\u003e\n  \u003c/thead\u003e\n  \u003ctbody\u003e\n    \u003ctr\u003e\n      \u003ctd rowspan=\"26\"\u003eMLSecOps\u003c/td\u003e\n      \u003ctd rowspan=\"3\"\u003eStage 1\u003c/td\u003e\n      \u003ctd\u003e\u003ca href=\"https://pre-commit.com/\"\u003ePre-Commit Hook Scans\u003c/td\u003e\n      \u003ctd\u003eA framework for managing and maintaining multi-language pre-commit hooks.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd\u003e\u003ca href=\"https://marketplace.visualstudio.com/items?itemName=AquaSecurityOfficial.trivy-vulnerability-scanner\"\u003eTrivy Vulnerability Scanner\u003c/a\u003e\u003c/td\u003e\n      \u003ctd\u003eComprehensive vulnerability scanner for containers and other artifacts.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://marketplace.visualstudio.com/items?itemName=trunk.io\"\u003eTrunk Check\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eAutomated Code Quality for Teams: universal formatting, linting, static analysis, and security.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"2\"\u003eStage 2\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://aws.amazon.com/s3/\"\u003eAWS S3 bucket\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eA bucket is a container for objects stored in Amazon S3.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.sonatype.com/products/sonatype-nexus-repository\"\u003eNexus Repository\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSonatype Nexus Repository\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"8\"\u003eStage 3\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://gitleaks.io/\"\u003eGitleak\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSecret scanner for git repositories, files, and directories.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.sonatype.com/products/sonatype-nexus-repository\"\u003eSonarqube\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eOpen-source platform for continuous inspection of code quality.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://aquasecurity.github.io/trivy/\"\u003eTrivy\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eComprehensive vulnerability scanner for containers and other artifacts.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://horusec.io/\"\u003eHorusec\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eTool to perform static code analysis to identify security flaws.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://owasp.org/www-project-dependency-check/\"\u003eOWASP Dependency-Check\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eTool that identifies project dependencies and checks for known vulnerabilities.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://nbdefense.ai/\"\u003eNB Defense\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSecurity tool for Jupyter notebooks, scanning for vulnerabilities and risks.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eCompliance check\u003c/td\u003e\n        \u003ctd\u003ePIC/DSS, ISO/IEC 27001, NIST 800-53B, ...\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/ioos/compliance-checker\"\u003ecompliance-checker\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003ePython tool to check your datasets against compliance standards\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 4\u003c/td\u003e\n        \u003ctd\u003eQuality Gate\u003c/td\u003e\n        \u003ctd\u003eDefine a rule/ policy for test result.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"2\"\u003eStage 5\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://keras.io/api/callbacks/early_stopping/\"\u003eEarlyStopping\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eStop training when a monitored metric has stopped improving.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://scikit-learn.org/stable/modules/generated/sklearn.model_selection.KFold.html\"\u003eKFold\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eK-Fold cross-validator.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 6\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://scikit-learn.org/stable/modules/model_evaluation.html\"\u003eEarlyStopping\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eMetrics and scoring: quantifying the quality of predictions.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"4\"\u003eStage 7\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/protectai/modelscan\"\u003emodelscan\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eProtection Against ML Model Serialization Attacks.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/deadbits/vigil-llm\"\u003eVigil\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eLLM prompt injection and security scanner.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/leondz/garak\"\u003eGarak\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eLLM vulnerability scanner.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/promptfoo/promptfoo\"\u003epromptfoo\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eLLM red teaming and evaluation framework with adversarial attacks.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 8\u003c/td\u003e\n        \u003ctd\u003eQuality Gate\u003c/td\u003e\n        \u003ctd\u003eDefine a rule/ policy for test result.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 9\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/openpubkey/openpubkey\"\u003eOpenPubKey\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eOpenPubkey is a protocol for leveraging OpenID Providers (OPs) to bind identities to public keys.\u003c/td\u003e\n    \u003c/tr\u003e    \n    \u003ctr\u003e\n        \u003ctd rowspan=\"2\"\u003eStage 10\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://aws.amazon.com/s3/\"\u003eAWS S3 bucket\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eA bucket is a container for objects stored in Amazon S3.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.sonatype.com/products/sonatype-nexus-repository\"\u003eNexus Repository\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSonatype Nexus Repository\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd rowspan=\"35\"\u003eDevSecOps\u003c/td\u003e\n      \u003ctd rowspan=\"3\"\u003eStage 1\u003c/td\u003e\n      \u003ctd\u003e\u003ca href=\"https://pre-commit.com/\"\u003ePre-Commit Hook Scans\u003c/td\u003e\n      \u003ctd\u003eA framework for managing and maintaining multi-language pre-commit hooks.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://marketplace.visualstudio.com/items?itemName=AquaSecurityOfficial.trivy-vulnerability-scanner\"\u003eTrivy Vulnerability Scanner\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eComprehensive vulnerability scanner for containers and other artifacts.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://marketplace.visualstudio.com/items?itemName=trunk.io\"\u003eTrunk Check\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eAutomated Code Quality for Teams: universal formatting, linting, static analysis, and security.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"2\"\u003eStage 2\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://aws.amazon.com/s3/\"\u003eAWS S3 bucket\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eA bucket is a container for objects stored in Amazon S3.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.sonatype.com/products/sonatype-nexus-repository\"\u003eNexus Repository\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSonatype Nexus Repository\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"10\"\u003eStage 3\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://gitleaks.io/\"\u003eGitleak\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSecret scanner for git repositories, files, and directories.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.sonatype.com/products/sonatype-nexus-repository\"\u003eSonarqube\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eOpen-source platform for continuous inspection of code quality.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://aquasecurity.github.io/trivy/\"\u003eTrivy\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eComprehensive vulnerability scanner for containers and other artifacts.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://horusec.io/\"\u003eHorusec\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eTool to perform static code analysis to identify security flaws.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://owasp.org/www-project-dependency-check/\"\u003eOWASP Dependency-Check\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eTool that identifies project dependencies and checks for known vulnerabilities.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.checkov.io/\"\u003eCheckov\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eCheckov scans cloud infrastructure configurations to find misconfigurations.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/terraform-linters/tflint\"\u003eTFlint\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eA Pluggable Terraform Linter.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://terraform-compliance.com/\"\u003eterraform-compliance\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eterraform-compliance is a lightweight, security and compliance focused test framework against terraform to enable negative testing capability for your infrastructure-as-code.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/aquasecurity/tfsec\"\u003etfsec\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003etfsec uses static analysis of your terraform code to spot potential misconfigurations.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd\u003e\u003ca href=\"https://github.com/openpubkey/openpubkey\"\u003eOpenPubKey\u003c/a\u003e\u003c/td\u003e\n      \u003ctd\u003eOpenPubkey is a protocol for leveraging OpenID Providers (OPs) to bind identities to public keys.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 4\u003c/td\u003e\n        \u003ctd\u003eQuality Gate\u003c/td\u003e\n        \u003ctd\u003eDefine a rule/ policy for test result.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 5\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://docs.docker.com/reference/cli/docker/buildx/build/\"\u003eBuild image\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eDocker buildx build.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"5\"\u003eStage 6\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://docs.snyk.io/scan-using-snyk/snyk-container/scan-container-images\"\u003eSynk\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSnyk Container helps you find and fix vulnerabilities in container images, based on container registry scans.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://docs.docker.com/scout/\"\u003eDocker Scount\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eScan docker image.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://portswigger.net/burp\"\u003eBurp Suite\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eThe class-leading vulnerability scanning, penetration testing, and web app security platform.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.acunetix.com/\"\u003eAcunetix\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eAcunetix is an end-to-end web security scanner.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.zaproxy.org/\"\u003eOWASP ZAP\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eZAP is a free and open source web application scanner that can help you find vulnerabilities and test your web applications.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 7\u003c/td\u003e\n        \u003ctd\u003eQuality Gate\u003c/td\u003e\n        \u003ctd\u003eDefine a rule/ policy for test result.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"2\"\u003eStage 8\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/openpubkey/openpubkey\"\u003eOpenPubKey\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eOpenPubkey is a protocol for leveraging OpenID Providers (OPs) to bind identities to public keys.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd\u003e\u003ca href=\"https://docs.docker.com/engine/security/trust/#docker-content-trust-keys\"\u003eDocker content trust key\u003c/a\u003e\u003c/td\u003e\n      \u003ctd\u003eTrust for an image tag is managed through the use of signing keys.\u003c/td\u003e\n    \u003c/tr\u003e    \n    \u003ctr\u003e\n        \u003ctd rowspan=\"2\"\u003eStage 9\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://aws.amazon.com/s3/\"\u003eAWS S3 bucket\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eA bucket is a container for objects stored in Amazon S3.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.sonatype.com/products/sonatype-nexus-repository\"\u003eNexus Repository\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSonatype Nexus Repository\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"6\"\u003eStage 10\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.tenable.com/products/nessus\"\u003eNessus\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eNessus Vulnerability Scanner.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://nmap.org/\"\u003eNmap\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eSecurity Scanner, Port Scanner, \u0026 Network Exploration Tool.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd\u003e\u003ca href=\"https://github.com/openpubkey/openpubkey\"\u003eOpenPubKey\u003c/a\u003e\u003c/td\u003e\n      \u003ctd\u003eOpenPubkey is a protocol for leveraging OpenID Providers (OPs) to bind identities to public keys.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd\u003e\u003ca href=\"https://docs.docker.com/engine/security/trust/#docker-content-trust-keys\"\u003eDocker content trust key\u003c/a\u003e\u003c/td\u003e\n      \u003ctd\u003eTrust for an image tag is managed through the use of signing keys.\u003c/td\u003e\n    \u003c/tr\u003e \n    \u003ctr\u003e\n        \u003ctd\u003eCompliance check\u003c/td\u003e\n        \u003ctd\u003ePIC/DSS, ISO/IEC 27001, NIST 800-53B, ...\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/OpenSCAP/openscap\"\u003eOpenSCAP\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eOpenSCAP is an open source project that provides tools and policies for managing system security and standards compliance\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 11\u003c/td\u003e\n        \u003ctd\u003eQuality Gate\u003c/td\u003e\n        \u003ctd\u003eN/A\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd rowspan=\"1\"\u003eStage 12\u003c/td\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/noobpk/gemini-self-protector\"\u003egemini-self-protector\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eGemini - Runtime Application Self Protection Solution (G-SP).\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd rowspan=\"7\"\u003eMonitoring\u003c/td\u003e\n      \u003ctd rowspan=\"7\"\u003eAll stage\u003c/td\u003e\n      \u003ctd\u003e\u003ca href=\"https://api.slack.com/messaging/webhooks\"\u003eSlack webhook\u003c/td\u003e\n      \u003ctd\u003eSending messages using incoming webhooks.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://core.telegram.org/bots/api\"\u003eTelegram Bot\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eTelegram Bot API.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.defectdojo.org/\"\u003eDeject Dojo\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eApplication vulnerability management tool.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.elastic.co/elastic-stack\"\u003eELK stack\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eElasticsearch, Logstash and Kibana.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://www.pagerduty.com/\"\u003ePagerDuty\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eAutomate, manage, and improve your operations with over 700 integrations and generative AI.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://prometheus.io/\"\u003ePrometheus\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003ePower your metrics and alerting with the leading open-source monitoring solution.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://grafana.com/\"\u003eGrafana\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eGrafana is the open source analytics \u0026 monitoring solution for every database.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n      \u003ctd rowspan=\"4\"\u003eKey Management\u003c/td\u003e\n      \u003ctd rowspan=\"4\"\u003eAll stage have use key or credential\u003c/td\u003e\n      \u003ctd\u003e\u003ca href=\"https://www.hashicorp.com/products/vault\"\u003eHashiCorp Vault\u003c/td\u003e\n      \u003ctd\u003eManage access to secrets and stop credentials from falling into the wrong hands with identity-based security.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://aws.amazon.com/kms/\"\u003eAWS Key Management Service\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eCreate and control keys used to encrypt or digitally sign your data.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://aws.amazon.com/secrets-manager/\"\u003eAWS Secrets Manager\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eCentrally manage the lifecycle of secrets.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003e\u003ca href=\"https://github.com/venkat22022202/black-vault\"\u003eBlackVault\u003c/a\u003e\u003c/td\u003e\n        \u003ctd\u003eProxy gateway for AI API keys. Agents never see the real key. Kill access instantly..\u003c/td\u003e\n    \u003c/tr\u003e    \n  \u003c/tbody\u003e\n\u003c/table\u003e\n\n## Best Practices\n\n- [OWASP LLMSVS](https://owasp.org/www-project-llm-verification-standard/)\n- [OWASP Top 10 for Large Language Model Applications](https://owasp.org/www-project-top-10-for-large-language-model-applications/)\n- [OWASP Machine Learning Security Top Ten](https://owasp.org/www-project-machine-learning-security-top-10/)\n- [MITRE ATLAS™ (Adversarial Threat Landscape for Artificial-Intelligence Systems)](https://atlas.mitre.org/)\n- [OWASP DevSecOps](https://devsecops.owasp.org/)\n- [OWASP Devsecops Maturity Model](https://owasp.org/www-project-devsecops-maturity-model/)\n- [OWASP DevSecOps Guideline](https://owasp.org/www-project-devsecops-guideline/)\n- [DevSecOps-Playbook-Securestack](https://github.com/6mile/DevSecOps-Playbook)\n- [DevSecOps-Department of Defense (DoD)](https://public.cyber.mil/devsecops/)\n\n## Case Studies\n\n- [Automating Application Security to Protect Corporate Data Assets at the Speed of Business](https://www.contrastsecurity.com/customer-success/asg-technologies)\n- [Enhancing the GuardRails solution](https://maddevs.io/case-studies/guardrails/)\n- [DevOps in Action: Real-world Case Studies](https://medium.com/@vinodvamanbhat/devops-in-action-real-world-case-studies-db7907149814)\n- [Large scale transformation with DevSecOps](https://www.capacitas.co.uk/ukhsa-case-study)\n\n## Community\n\n- [MLSecOps Community](https://community.mlsecops.com/)\n- [DevSecOps](https://dev.to/t/devsecops)\n- [DevSecCon](https://www.devseccon.com/)\n\n## Contribution\n\nWe welcome contributions from the community to help us expand and improve this repository. If you have suggestions, tools, or resources that you believe should be included, please feel free to submit a pull request or open an issue.\n\nThank you for visiting our repository. We hope you find it a valuable resource in your journey towards secure and effective machine learning operations.\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/noobpk%2Fmlsecops-devsecops-awesome/projects"}