{"adoption": {"forks": 262, "observed_at": "2026-08-28T04:03:34.957480+00:00", "stars": 1098}, "canonical_url": "https://ross.abutalabs.com/products/devsecopsguideline", "card": {"archived": false, "artifact_type": "learning-resource", "description": "The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.", "domain": ["security", "developer-tools", "documentation"], "enriched": true, "function": ["security", "developer-tools", "documentation", "ci-cd"], "health_score": 75, "homepage": "https://owasp.org/www-project-devsecops-guideline/", "language": "Python", "license": "NOASSERTION", "license_family": "other", "maturity": "active", "member_repos": ["OWASP/DevSecOpsGuideline"], "name": "OWASP/DevSecOpsGuideline", "platform": ["cross-platform", "cli"], "pushed_at": "2026-07-11T16:46:23+00:00", "repo": "OWASP/DevSecOpsGuideline", "stars": 1098, "tags": ["devsecops", "shift-left", "owasp", "sast", "dast", "sca", "iac-scanning", "supply-chain-security", "guideline", "devops", "docker"], "topics": ["devsecops", "owasp", "shift-left", "security"], "urls": [], "use_cases": ["how to add security scanning to my CI/CD pipeline", "shift-left security best practices", "what is SAST vs DAST vs SCA", "scan terraform and helm charts for misconfigurations", "prevent credentials leaking in git repositories", "software supply chain security with SBOM and artifact signing", "secure devops pipeline checklist", "compliance checks in the development pipeline"], "what_it_is": "An OWASP project providing a guideline for embedding security into DevOps/CI-CD pipelines, covering practices like SAST, DAST, SCA, IaC scanning, and supply-chain security. It is primarily documentation and best-practice guidance rather than a runnable tool.", "when_to_avoid": ["you need a runnable scanner or tool rather than guidance", "you need runtime security enforcement rather than documentation", "you need OWASP Top 10 application controls specifically (see Proactive Controls)"], "when_to_choose": ["designing or improving a secure CI/CD pipeline", "introducing shift-left security culture in an engineering team", "selecting tools for SAST, DAST, SCA, or IaC scanning", "training developers on DevSecOps practices"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/devsecopsguideline", "repo": "OWASP/DevSecOpsGuideline", "role": "main", "score": 74}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:34.957480+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:46:13.093780+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "771ecc7dee86271e07fe22eed24f24895ea956cc3c3ff61099098d6d171a617c", "fetched_at": "2026-08-28T04:03:34.957480+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OWASP/DevSecOpsGuideline"}, {"content_hash": "aca8435eec21e9ff4e8f7c40f5ac842cbd8b1cdbfbe40235ddcf6e5182bc854a", "fetched_at": "2026-08-29T12:49:42.731515+00:00", "kind": "homepage", "missing": false, "url": "https://owasp.org/www-project-devsecops-guideline/"}, {"content_hash": "b21a48297b2dfd11edd59c3260c39b8f6b66d133bc13ef23c0a1b56af49ff526", "fetched_at": "2026-08-29T12:49:42.776286+00:00", "kind": "site_page", "missing": false, "url": "https://owasp.org/about"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 92, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2301, "days_push": 53, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 74, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}