Projects with this topic
-
The policy plane. Pipeline Execution Policy, security policies, and external compliance controls that assess and gate every consumer.
Updated -
Skaledheim (SKM) is a modular platform designed to orchestrate distributed services inside a cohesive DevSecOps cluster oriented ecosystem.
Updated -
Landing page for the Evidence Factory group. Start here for the guided walk through the six projects.
Updated -
-
Consumer workload: a reusable CI/CD Catalog component. Adoption phase enforce, so an off-catalog include is blocked. The red pipeline is deliberate: the gap is planted so a reader can watch the gate stop it.
Updated -
Consumer workload: a container image. Adoption phase cutover, so the regulatory baseline blocks an unsigned image. The red pipeline is deliberate: the gap is planted so a reader can watch the gate stop it.
Updated -
Fix agent reliability issues in GitLab CI/CD across Claude Agent SDK, OpenAI Agents SDK, Google ADK, MCP, LangChain, LangGraph, CrewAI, AutoGen AG2, Pydantic AI, and Vercel AI. Gates pipelines on risk and severity.
Updated -
DevSecOps health check for GitLab Self-Managed instances.
Updated -
This GitLab CI/CD pipeline implements a complete DevSecOps and GitOps workflow for a containerized application. It performs Dockerfile linting, builds and pushes images with Kaniko, runs Gitleaks and Trivy security scans, generates a CycloneDX SBOM, updates Kubernetes manifests through GitOps, performs DAST using OWASP ZAP and Nuclei, and generates a unified HTML security report with all scan results.
Updated -
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
-
Toolchain image for the Coroboros security gates.
UpdatedUpdated -
Always-on GitLab repo custodian: an autonomous AI teammate (4 personas) that reviews merge requests, sweeps merged code for regressions, files issues, and drafts fix MRs — tuning itself to your team's standards from your reactions. Built on Vertex AI Gemini + GitLab MCP for the Google Cloud Rapid Agent Hackathon 2026 (GitLab Track).
Updated -
Consumer workload: a Go binary. Adoption phase report, so conformance runs advisory and merge requests stay green.
Updated -
The driver. One tool that provisions the group, applies the NIST 800-53 framework, pushes control evidence, and exports the control allocation as an OSCAL component-definition.
Updated -
The evidence line and the published CI/CD Catalog. Governed, reusable pipeline components every workload builds from.
Updated -
This repository manages the deployment and automated security scanning of OWASP Juice Shop
Updated -
Shared CI/CD components for the Mandrel Project: commit linting, security scanning, tests, semantic versioning, and artifact publishing for Go services, Go modules, and specification bundles.
Updated -
Probably the most modern and sophisticated insecure web application!
Clone of OWASP Juice Shop with GitLab branding and more.
Learn more by seeing our DevSecOps Tutorial
Updated