Projects with this topic
-
SortSmart waste-sorting advisor + Duo Agentic Ship-It Loop — GitLab Transcend (Life After Code) hackathon entry. Every push/MR runs Duo agents across the DevSecOps lifecycle: review, secure, verify, deploy, monitor.
Updated -
Commento, kept alive by deadhand: a dead man's switch for open source. A written mandate, two keys and a canary let GitLab Duo agents maintain an abandoned project while nobody's at the wheel. Community fork of Commento (MIT), not affiliated with Commento, Inc.
Updated -
Find release-order failures that green MR CI misses. GitLab Duo proposes falsifiable experiments; GitLab CI proves evidence-backed release waves.
Updated -
Landing page, ten scenarios, claims ledger and a posture mirror an assessor can check without an account. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
DevSecOps health check for GitLab Self-Managed instances.
Updated -
Deterministic, format-preserving dependency remediation for GitLab CI — Maven first. A hundred eyes on your dependency graph.
Updated -
Renders the group README and its ten scenarios as one site. Holds no prose; edit gitlab-profile. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
🗳️ Votely is a polling web app (React, FastAPI, PostgreSQL) built as a DevOps showcase: the application is the pretext, the delivery platform is the point.✅ Tests from unit to end-to-end, a GitLab CI pipeline with security gates (gitleaks, Semgrep, Trivy, SBOM), build-once/promote releases, Helm charts for Kubernetes, AWS infrastructure with Terraform, keyless CI access through OIDC, images signed with Cosign and AWS KMS, k3s on EC2 with a disposable server and persistent data, HTTPS with cert-manager and Let's Encrypt, GitOps with Argo CD (staging on every merge, production on release tags, rollback by git revert, Sealed Secrets).🚧 Next: observability (Prometheus, Grafana).📖 Documented in English and French.Updated -
Chapter 6: a CI component at enforce phase. A planted off-catalog include stays red: the gate stops it. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
Chapter 5: a container image at cutover phase. A planted unsigned-image gap stays red: the floor blocks it. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
Chapter 4: a Go binary at report phase. Gaps are published and advisory, so the merge request stays green. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
Chapter 3: the driver. One tool provisions the group, assesses controls, pushes verdicts and exports OSCAL. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
Chapter 2: the policy plane. The NIST 800-53 framework, the policy that injects the line, approval gates. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
Chapter 1: the governed CI/CD Catalog and evidence line, with pinned components every workload builds from. Guide: https://evidence-factory.gitlab.io/guide/
Updated -
Probably the most modern and sophisticated insecure web application!
Clone of OWASP Juice Shop with GitLab branding and more.
Learn more by seeing our DevSecOps Tutorial
Updated -
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
Skaledheim (SKM) is a modular platform designed to orchestrate distributed services inside a cohesive DevSecOps cluster oriented ecosystem.
Updated -
Receipted Pipeline: an AI agent runs the full post-code DevSecOps lifecycle (review, security, test, deploy, monitor) hands-off on GitLab, and every stage leaves a verifiable execution receipt (AER-1). GitLab Transcend hackathon Path B entry.
Updated -
Toolchain image for the Coroboros security gates.
UpdatedUpdated -
Enterprise-grade toolkit to audit and migrate legacy infrastructure to hybrid post-quantum cryptography (PQC).
Updated