function: ci-cd
424 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| antonbabenko/pre-commit-terraform A collection of git hooks for Terraform, OpenTofu, and Terragrunt driven by the pre-commit framework. It automatically formats code and run… | 99 | 3760 | active |
| jstrieb/github-stats A tool that generates GitHub profile and repository statistics visualizations as SVG images using GitHub Actions, including data from priva… | 93 | 3542 | active |
| stackrox/kube-linter KubeLinter is a static analysis CLI tool that checks Kubernetes YAML files, Helm charts, and Kustomize manifests against security and produ… | 86 | 3501 | active |
| commitizen-tools/commitizen Commitizen is a Python CLI tool that enforces standardized commit messages (Conventional Commits by default) and automates semantic version… | 95 | 3498 | active |
| WordPress/wordpress-develop The official Git mirror of the WordPress core development repository (synced from Subversion), containing the PHP, MySQL, and JavaScript so… | 77 | 3419 | stable |
| FairwindsOps/polaris Polaris is an open source policy engine for Kubernetes that validates and remediates resource configuration against 30+ built-in best-pract… | 98 | 3384 | active |
| SQLMesh/sqlmesh SQLMesh is a scalable data transformation framework for running and deploying SQL or Python data models, backward compatible with dbt. It p… | 93 | 3256 | active |
| open-policy-agent/conftest Conftest is a CLI utility for writing tests against structured configuration data using the Open Policy Agent Rego language. It validates f… | 98 | 3249 | active |
| dembrandt/dembrandt Dembrandt is an open-source Node.js CLI that extracts a website's design system—colors, typography, spacing, borders, shadows, motion, comp… | 83 | 3225 | active |
| yannh/kubeconform Kubeconform is a fast Kubernetes manifest validator written in Go, inspired by Kubeval. It validates YAML manifests against JSON schemas, s… | 78 | 3162 | active |
| sqitchers/sqitch Sqitch is a standalone database change management (migration) tool that tracks schema changes as native SQL scripts with a plan file and Me… | 83 | 3155 | stable |
| zegl/kube-score kube-score is a static code analysis tool for Kubernetes object definitions that scores manifests and Helm charts against reliability and s… | 60 | 3102 | active |
| danielpalme/ReportGenerator ReportGenerator is a command-line tool that converts code coverage reports from tools like coverlet, OpenCover, dotCover, Cobertura, JaCoCo… | 97 | 3090 | active |
| Chachamaru127/claude-code-harness A development harness plugin for Claude Code (and Codex CLI, Cursor, Grok) that enforces a disciplined Plan→Work→Review→Release loop with s… | 79 | 3072 | active |
| michaelshimeles/ralphy Ralphy is a CLI tool (npm package and bash script) that runs AI coding agents like Claude Code, Codex, OpenCode, Cursor, Qwen-Code, and Fac… | 45 | 2964 | active |
| projen/projen projen is a CLI tool and library that synthesizes project configuration files (package.json, tsconfig.json, GitHub Workflows, linting, CI/C… | 95 | 2948 | active |
| sagiegurari/cargo-make cargo-make is a Rust task runner and build tool that lets developers define and run task flows via TOML-based Makefile.toml files. It works… | 64 | 2946 | stable |
| testem/testem Testem is a JavaScript test runner that executes tests in real desktop browsers (Chrome, Firefox, Safari, Edge), Node, or custom launchers.… | 95 | 2917 | active |
| tach-org/tach Tach is a CLI tool, written in Rust, that enforces dependency rules and public interfaces between Python modules to support a modular monol… | 77 | 2801 | active |
| microsoft/promptflow Prompt flow is a suite of Python SDK, CLI, and VS Code extension tools for the end-to-end development of LLM-based AI applications, linking… | 75 | 11229 | maintenance |
| erda-project/erda Erda is an enterprise-grade cloud-native application platform built on Kubernetes that provides DevOps, microservice governance, and multi-… | 67 | 2750 | active |
| postgres-ai/database-lab-engine DBLab Engine is an open-source platform that provides instant, full-size thin clones and branching of PostgreSQL databases using ZFS copy-o… | 89 | 2697 | active |
| prontolabs/pronto Pronto is a Ruby gem that runs automated code review by analyzing only the changes in a diff rather than the whole codebase. It integrates … | 69 | 2670 | active |
| FairwindsOps/pluto Pluto is a Go command-line utility from Fairwinds that detects deprecated and removed Kubernetes apiVersions in static manifests, Helm char… | 98 | 2570 | stable |
| friendlyanon/cmake-init cmake-init is an opinionated command-line tool that scaffolds modern CMake projects for executables, static/shared libraries, and header-on… | 64 | 2542 | active |
| mattzcarey/shippie Shippie is an extendable AI code-review agent that reads pull request diffs, explores the codebase with developer tools, and posts focused … | 92 | 2483 | active |
| EmbarkStudios/cargo-deny cargo-deny is a Cargo plugin (cargo subcommand) for linting Rust dependency graphs. It checks crate licenses against allow/deny lists, bans… | 97 | 2407 | active |
| youlaitech/youlai-mall youlai-mall is an open-source full-stack e-commerce mall system built with Spring Boot 3, Spring Cloud & Alibaba 2022, Spring Authorization… | 42 | 2366 | active |
| jaywcjlove/github-rank A GitHub user and repository ranking site that publishes global and China leaderboards of GitHub users by followers and repositories by sta… | 98 | 2308 | active |
| wemake-services/wemake-django-template A bleeding-edge Cookiecutter template for scaffolding Django projects with a strong focus on code quality, security, and scalability. It sh… | 67 | 2268 | active |
| kuberhealthy/kuberhealthy Kuberhealthy is a Kubernetes operator that runs synthetic monitoring checks as short-lived pods, defined via HealthCheck custom resources. … | 99 | 2264 | active |
| pyscaffold/pyscaffold PyScaffold is a Python project generator that bootstraps high-quality, PyPI-ready package templates via the `putup` command. It bundles bes… | 67 | 2263 | stable |
| livecycle/preevy Preevy is an open-source CLI tool that provisions, manages, and exposes ephemeral preview environments for Docker Compose applications in t… | 58 | 2226 | active |
| learnhouse/learnhouse LearnHouse is a next-generation open-source learning management system (LMS) for creating, sharing, and selling educational content. It com… | 99 | 2203 | active |
| SignTools/SignTools SignTools is a free, self-hosted platform for signing and sideloading iOS, iPadOS, and macOS apps without needing a computer on hand. It pa… | 92 | 2202 | active |
| openstack/devstack DevStack is a set of shell scripts and utilities that quickly deploy a full OpenStack cloud from upstream git source trees on a clean Ubunt… | 75 | 2143 | active |
| oss-review-toolkit/ort The OSS Review Toolkit (ORT) is a FOSS policy automation toolkit that analyzes project dependencies, scans licenses and copyrights, checks … | 95 | 2075 | active |
| microsoft/sbom-tool Microsoft's SBOM Tool is a scalable, enterprise-ready CLI that generates SPDX 2.2 and SPDX 3.0 compatible Software Bill of Materials docume… | 81 | 2068 | active |
| konstructio/kubefirst Kubefirst is a CLI that provisions instant GitOps-based Kubernetes platforms, integrating tools like Argo CD, Atlantis, Vault, and external… | 75 | 2057 | active |
| microcks/microcks Microcks is an open source, cloud native platform for API mocking and testing that turns OpenAPI, AsyncAPI, gRPC, GraphQL, Postman and Soap… | 98 | 2026 | active |
| pyupio/safety Safety CLI is a Python dependency vulnerability scanner that detects packages with known vulnerabilities and malicious packages in local de… | 94 | 1995 | active |
| GitGuardian/ggshield ggshield is a CLI application from GitGuardian that detects over 500 types of hardcoded secrets in files, git history, and CI environments … | 99 | 1992 | active |
| fabric8io/docker-maven-plugin A Maven plugin for building Docker images and managing Docker containers directly from the Maven build lifecycle. It supports goals for bui… | 87 | 1933 | active |
| google-github-actions/setup-gcloud A GitHub Action that installs and configures the Google Cloud SDK (gcloud CLI) within GitHub Actions workflows. It supports version constra… | 70 | 1906 | active |
| aquasecurity/tfsec tfsec is a static analysis security scanner for Terraform code that detects misconfigurations across major cloud providers using hundreds o… | 59 | 7035 | maintenance |
| Serverless-Devs/Serverless-Devs Serverless Devs is an open-source serverless developer toolchain and CLI (installed via npm as @serverless-devs/s) for managing the full li… | 63 | 1831 | active |
| athul/waka-readme A GitHub Action that fetches WakaTime coding metrics and injects weekly development statistics into your GitHub profile README. It runs on … | 53 | 1830 | active |
| aquaproj/aqua aqua is a declarative CLI version manager written in Go that manages tool versions per project via configuration files, with lazy installat… | 94 | 1819 | active |
| moxi624/mogu_blog_v2 MoguBlog is a front-end/back-end separated blog system built on a Java microservices architecture (Spring Cloud + Spring Boot + MyBatis-Plu… | 33 | 1807 | active |
| metlo-labs/metlo Metlo is an open-source API security platform that inventories API endpoints, detects malicious traffic in real time, and can automatically… | 38 | 1783 | active |
| towardsthecloud/cloudburn CloudBurn is an open-source AWS cost policy engine distributed as a CLI, SDK, and GitHub App. It runs deterministic cost rules against Terr… | 96 | 1777 | active |
| graphql-hive/graphql-inspector GraphQL Inspector is a suite of tools for validating and monitoring GraphQL schemas. It diffs two schemas to flag breaking, dangerous, or n… | 98 | 1760 | stable |
| murphysecurity/murphysec MurphySec CLI is an open-source software composition analysis (SCA) tool that detects vulnerable dependencies in projects from the command … | 57 | 1753 | active |
| GoogleCloudPlatform/agent-starter-pack A Python package from Google Cloud Platform that provides production-ready templates for building and deploying GenAI agents on Google Clou… | 74 | 6545 | maintenance |
| Yelp/paasta PaaSTA is an open-source, distributed platform-as-a-service from Yelp for building, deploying, and monitoring containerized services on Kub… | 95 | 1729 | stable |
| obi1kenobi/cargo-semver-checks cargo-semver-checks is a CLI linter that scans Rust crates for semantic versioning violations by comparing a crate's public API against a p… | 94 | 1673 | active |
| kenn-io/roborev roborev is a Go-based continuous code review tool for AI coding agents that reviews every commit in the background via git hooks and surfac… | 78 | 1669 | active |
| python/pythondotorg The Django-based source code that powers the official python.org website, built with PostgreSQL, Redis, and Celery. It is maintained by the… | 77 | 1656 | active |
| kubeshop/testkube Testkube is an open testing platform that orchestrates, executes, and analyzes automated tests inside Kubernetes infrastructure using any c… | 95 | 1649 | active |
| gjtorikian/html-proofer HTMLProofer is a Ruby tool that validates rendered HTML files, checking for broken internal and external links, missing image alt tags, inv… | 91 | 1646 | active |
| crate-ci/cargo-release cargo-release is a Cargo subcommand that streamlines releasing Rust crates by extending `cargo publish` with validation, version bumping, t… | 98 | 1588 | stable |
| TraceMachina/nativelink NativeLink is a high-performance remote build cache and remote execution server written in Rust, speaking the open Remote Execution API. It… | 99 | 1577 | active |
| awslabs/diagram-as-code A Go-based CLI tool (awsdac) that generates AWS architecture diagrams from human-readable YAML definitions, following AWS diagram guideline… | 88 | 1559 | active |
| cpisciotta/xcbeautify xcbeautify is a fast, Swift-based formatter that beautifies xcodebuild and Swift Package Manager output with human-friendly colored logs. I… | 91 | 1536 | active |
| fossas/fossa-cli FOSSA CLI is a zero-configuration, language-agnostic dependency analysis tool that detects dependencies in any codebase across 20+ build sy… | 95 | 1516 | active |
| dnsjia/luban LuBan is a self-hosted Kubernetes multi-cluster management and operations platform built with Go (Gin/Gorm) and Vue 3, integrating CMDB ass… | 35 | 1508 | active |
| hxhb/HotPatcher HotPatcher is an Unreal Engine (UE4.21–UE5) editor plugin for managing hot update versions and packaging resource patches. It tracks asset … | 52 | 1506 | active |
| actiontech/sqle SQLE is a self-hosted SQL quality management platform that audits, monitors, and governs SQL across its full lifecycle, from development-ti… | 96 | 1499 | active |
| mkubaczyk/helmsman Helmsman is a Helm Charts as Code tool that lets you describe the desired state of Kubernetes applications in a declarative TOML or YAML fi… | 87 | 1495 | active |
| pluralsh/plural Plural is an enterprise Kubernetes management platform that provides fleet-scale GitOps deployments, infrastructure-as-code management, and… | 95 | 1492 | active |
| invertase/melos Melos is a CLI tool for managing Dart and Flutter monorepos containing multiple packages. It automates versioning, changelog generation, an… | 67 | 1483 | active |
| ipetkov/crane Crane is a Nix library for building Cargo (Rust) projects with incremental artifact caching so dependencies are built only once. It provide… | 98 | 1450 | active |
| ossf/allstar Allstar is a GitHub App from OpenSSF that continuously monitors GitHub organizations and repositories for adherence to security best practi… | 74 | 1444 | active |
| fmind/mlops-python-package A Python package template that provides a production-grade code base with MLOps best practices for building and deploying machine learning … | 91 | 1415 | active |
| ifindev/fullstack-next-cloudflare A production-ready full-stack template combining Next.js 15 with Cloudflare Workers, including D1 database, R2 storage, Better Auth, and Se… | 48 | 1401 | active |
| JoshuaKGoldberg/create-typescript-app A quickstart-friendly TypeScript project template and CLI scaffolding tool that sets up new or existing repositories with comprehensive, op… | 95 | 1389 | active |
| ixrjog/opscloud4 OpsCloud4 is a self-hosted cloud operations platform built with Spring Boot that provides a bastion host with web/SSH terminals, Kubernetes… | 59 | 1386 | active |
| docker/setup-buildx-action An official GitHub Action that sets up Docker Buildx in CI workflows, creating and booting a builder using the docker-container driver. It … | 94 | 1373 | stable |
| cloudposse/atmos Atmos is an open-source CLI runtime for infrastructure that orchestrates Terraform, OpenTofu, Kubernetes, Helm, and containers through decl… | 95 | 1362 | active |
| ZupIT/horusec Horusec is an open-source SAST (static application security testing) CLI that scans a project for vulnerabilities across many languages wit… | 67 | 1333 | active |
| kubeshop/tracetest Tracetest is an open-source trace-based testing tool that builds integration and end-to-end tests on top of OpenTelemetry distributed trace… | 45 | 1328 | active |
| kodustech/kodus-ai Kodus (Kody) is an open-source AI code review agent that reviews pull requests on GitHub, GitLab, Bitbucket, and Azure Repos. It is model-a… | 82 | 1326 | active |
| jakzal/phpqa A Docker image bundling popular PHP static analysis and quality tools such as PHPStan, PHP-CS-Fixer, PHPMD, PHPCS, PHPCPD, PHPMetrics, and … | 94 | 1321 | active |
| owasp-dep-scan/dep-scan OWASP dep-scan is a security and risk audit CLI tool that scans project dependencies in local repositories and container images for known C… | 97 | 1281 | active |
| microsoft/waza Waza is a Go CLI from Microsoft for evaluating AI agent skills through structured benchmarks. Users define test cases and validation rules … | 81 | 1280 | active |
| stategraph/stategraph Stategraph is a platform that replaces Terraform/OpenTofu's file-based state with a Postgres-backed dependency graph, enabling resource-lev… | 86 | 1279 | active |
| tcnksm/ghr ghr is a Go CLI tool that creates GitHub Releases and uploads build artifacts to them in parallel. It reads repository info from .git/confi… | 91 | 1261 | active |
| siliconcompiler/siliconcompiler SiliconCompiler is a modular Python-based hardware build system that automates the flow from RTL source code (Verilog, VHDL, Chisel, etc.) … | 100 | 1206 | active |
| suzuki-shunsuke/pinact pinact is a Go CLI that pins GitHub Actions and Reusable Workflows to full commit SHAs in workflow and composite action files, adding versi… | 96 | 1188 | active |
| QuiiBz/sherif Sherif is an opinionated, zero-config linter for TypeScript and JavaScript monorepos, written in Rust for speed. It checks package. consist… | 88 | 1182 | active |
| Jwuthri/Tracely-ai Tracely is a self-hosted, trace-native CI/CD and observability platform for AI agents. It ingests agent traces over OpenTelemetry, grades t… | 58 | 1181 | active |
| cocogitto/cocogitto Cocogitto is a Rust CLI toolbox for the Conventional Commits and SemVer specifications. It helps create compliant commits, automatically bu… | 72 | 1179 | active |
| sbdchd/squawk Squawk is a linter for Postgres migrations and SQL that catches statements which could cause downtime, such as blocking locks or breaking s… | 96 | 1166 | active |
| fastforgedev/fastforge Fastforge (formerly Flutter Distributor) is an all-in-one CLI tool for building, packaging, and publishing Flutter applications across Andr… | 73 | 1137 | active |
| Gentleman-Programming/gentleman-guardian-angel Gentleman Guardian Angel (gga) is a pure-Bash CLI tool that runs AI-powered code reviews on staged files via a git pre-commit hook, using a… | 77 | 1135 | active |
| pullfrog/pullfrog Pullfrog is an open-source, model-agnostic GitHub bot that runs coding agents (Claude, Codex, etc.) inside your repo's GitHub Actions. It t… | 81 | 1111 | active |
| safedep/vet vet is an open-source CLI tool for software composition analysis that scans open-source dependencies for malicious packages and vulnerabili… | 93 | 1103 | active |
| buildpacks-community/kpack kpack is a Kubernetes-native container build service that implements Cloud Native Buildpacks to build OCI images from source code. It provi… | 92 | 1081 | active |
| maester365/maester Maester is a PowerShell-based test automation framework that monitors and validates the security configuration of Microsoft 365 and Entra I… | 88 | 1080 | active |
| cdxgen/cdxgen cdxgen is a CLI tool, library, and server that creates CycloneDX Bill of Materials (SBOM) documents from source code and container images, … | 95 | 1060 | active |