Projects with this topic
-
-
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
Cheatsheet / IT toolbox
Updated -
AI-powered security orchestration for GitLab CI/CD. Automated vulnerability patching, threat modeling, and compliance scoring with GPT-4 and Claude AI agents.
Updated -
Static security scanner for MCP and AI-agent configurations ? secrets, excessive permissions, unsafe shells and supply-chain risk.
Updated -
D3FENDer is a security assessment and gap detection tool developed by Michael Favvas for his thesis titled "Development of a security assessment and gap detection system using the MITRE ATT&CK and D3FEND Frameworks". It uses a rule based system to grade an organization's defenses based on the input. It then detects possible gaps and suggests mitigations based on the MITRE ATT&CK and D3FEND Knowledge Bases. The tool can be used in SOC work flows.
Updated -
Always-on GitLab repo custodian: an autonomous AI teammate (4 personas) that reviews merge requests, sweeps merged code for regressions, files issues, and drafts fix MRs — tuning itself to your team's standards from your reactions. Built on Vertex AI Gemini + GitLab MCP for the Google Cloud Rapid Agent Hackathon 2026 (GitLab Track).
Updated -
AI-powered incident classification for ITSM environments. Python, FastAPI, Claude API, ChromaDB, BM25. Full CI/CD pipeline with SAST and dependency scanning.
Updated -
-
About FreePlayground is my public engineering lab notebook and proof-of-work repo. It captures weekly progress across DevOps fundamentals, cloud, automation, and security, plus the projects and experiments I build along the way.
Updated -
-
An AI-powered Security Agent built for the GitLab Duo Agent Challenge. Security Guardian automates vulnerability detection and provides suggested fixes directly in the SDLC.
Updated -
This basic note-taking application is used to showcase the different GitLab features around security and governance. To get started checkout the Full Tutorial Documentation.
Archived 12Updated -
🛡️ K-Guard: Kubernetes Security Automation & Remediation (PoC)K-Guard is a DevSecOps proof-of-concept focused on automating vulnerability lifecycle and active defense workflows within K3s clusters.
Vulnerability Remediation: Automated image patching workflows using K8s API patches triggered by Trivy scan results. Network Segregation: Policy-as-Code implementation (Ansible) for Ingress hardening and CIDR-based access control. SecOps Alerting: Real-time incident notification system leveraging Cisco Webex API for rapid response. Self-Healing Exploration: Detecting configuration drifts and applying automated state recovery.🛡️ K-Guard : Pilotage de la Sécurité & Automatisation Kubernetes (MVP)K-Guard est un outil d'expérimentation DevSecOps conçu pour automatiser les workflows de détection et de remédiation sur clusters K3s. Il explore l'implémentation de la défense active via l'API Kubernetes.
Points Techniques Clés
Vulnerability Management : Pipeline de scan continu (Trivy) avec déclenchement de correctifs via Strategic Merge Patch sur les Deployments. Hardening Réseau : Automatisation de Network Policies (Ansible) pour l'isolation des flux Ingress (filtrage IPs Cloudflare / RFC 1918). Incident Response (IR) : Système d'alerte ChatOps via l'API Cisco Webex pour la notification en temps réel des failles critiques détectées. Infrastructure-as-Code : Logique de remédiation et de déploiement orchestrée via GitLab CI/CD et scripts d'automation (Python/Go).Updated -
GitLab Duo Coffee Chat, hosted by @dnsmichi Guest: Michael Aigner, @tonka3000
Archived 0Updated -
A fully automated 13-stage DevSecOps CI/CD pipeline that integrates security, compliance, and cloud-native deployment using GitLab CI and Amazon EKS.
The pipeline demonstrates real-world DevSecOps practices including:
• SAST, dependency, container, IaC, and Kubernetes manifest scanning • SBOM generation (CycloneDX) • Automated POA&M creation mapped to NIST controls • Evidence packaging for compliance audits • Secure image push to Amazon ECR • Deployment and validation on Amazon EKS • Full run-to-completion behavior (lab mode) with findings documented rather than blocking
This project showcases an end-to-end secure software supply chain workflow suitable for: cloud engineering, DevOps, cybersecurity, and compliance automation demonstrations.
Updated -
This repository provides a comprehensive, production-grade blueprint for a modern DevSecOps pipeline. It showcases the integration of GitLab CI/CD, Terraform, HashiCorp Vault, and various security tools to build, test, and deploy a containerized Python application to AWS securely and efficiently.
Updated -
--The alphabet is not language but a circuit of cognition.
Updated -
This project serves as a comprehensive reference implementation for enterprise DevSecOps practices, demonstrating how security, automation, and observability integrate seamlessly in modern cloud applications.
Updated