Simple and pratical security gate for Github Security Alerts
-
Updated
Aug 11, 2026 - Perl
Simple and pratical security gate for Github Security Alerts
Security-Goat is a command line client to perform Security Gate written in Go. It interacts with DependaBot alerts using GitHub GraphQL API.
Mantis is a template-driven DAST and application validation engine for CI/CD pipelines - smoke tests, passive/active scanning, OpenAPI-driven API checks and an environment-aware security gate, in one deterministic tool.
Certify AI agents are safe for your internal web app before granting production access. CLI + MCP server, npm/PyPI.
DevSecOps CI/CD pipeline utilizing GitHub Actions to implement automated security gates and continuous security scanning for application workflows.
Self-building hardened RHEL 9 lab — CIS/STIG remediation as code, measured before/after
Security scan orchestrator and merge gate for CI. Runs Semgrep, Gitleaks and Trivy, merges results into SARIF, reports to your tracker and fails the pipeline only on new findings.
Docker Build & Trivy Vulnerability Scanning Pipeline
Security findings are generated by industry-standard scanners (Bandit, pip-audit, Gitleaks) and enforced via a custom Python policy-as-code gate, with optional AI-assisted remediation summaries.
Hands-on DevSecOps demo: a hardened, multi-stage Docker build for a Flask app with a Trivy CI security gate, SBOM generation (Syft), Docker Scout scanning, digest-pinned base images, and documented CVE exceptions. Build fails on HIGH/CRITICAL vulns.
IaC security gate — pre-commit + CI blocking secrets and misconfig before merge
Add a description, image, and links to the security-gate topic page so that developers can more easily learn about it.
To associate your repository with the security-gate topic, visit your repo's landing page and select "manage topics."