A working-engineer's devops and devsecops reference for Trivy, Semgrep, Checkov, Grype, Syft, TruffleHog, Cosign, OPA, Falco, Vault, Terraform, and more.
New here? Start at the learning path. It walks you from first-contact to confident in a sensible order — read that before this table.
A working devops and devsecops engineer's quick-reference: first-contact notes, runnable snippets, and configs for the tools you reach for every day. Use it as a shelf you grab from, not a tutorial site. It deliberately does not try to replace each tool's official docs.
A curated collection of notes, scripts, snippets, and templates covering vulnerability scanning, secret detection, supply chain security, runtime security, policy engines, and infrastructure automation. Every entry is scenario-grounded and designed to be adapted for real infrastructure work. The kit spans 32 tools organised for quick lookup and hands-on practice.
- Trivy ignore-rules pipeline — Trivy vulnerability scanning pipeline with custom ignore rules
- Verifying Trivy paths after restructure — Confirming Trivy how-to guide paths after directory changes
- Multi-arch vulnerability scanning with Trivy — Scanning multi-architecture images and manifests
- Syft output format comparison notebook — SPDX vs CycloneDX vs GitHub vs native JSON side by side
- Syft + Trivy Kubernetes scan scaffold — SBOM generation and vulnerability gating for workload images
00_index/— Navigation: topic map, quick links, glossary, learning pathassets/— Architecture diagrams and workflow illustrationsdocs/— Concepts, how-to guides, reference, runbooks, security docs, troubleshooting, and setup guidessnippets/— Copy-paste ready cheatsheets and one-linerstemplates/— Starter configs for Kubernetes, Terraform, Linux, Jenkins, Logstash, syslog-ngscripts/bash/— Shell toolkit scripts organised by tool (ansible, docker, k8s, linux, terraform, vault, jenkins, kafka, observability, etc.)environments/— Terraform environment configs (dev / staging / prod)lab/— Mini-projects and learning sandboxes.github/— Repo hygiene (CODEOWNERS, PR template, Dependabot config)
Per-tool content folders, each with notes/, scripts/, configs/, snippets/, and wherever useful docs/, manifests/, dockerfiles/, notebooks/, policies/, or templates/:
Trivy, Semgrep, Checkov, Grype, Syft, TruffleHog, GitGuardian, Snyk, Terrascan, CodeQL, ZAP, Cosign, Falco, Tetragon, OPA, Vault, Ansible, ArgoCD, Dependabot, Docker, Git, GitHub Actions, Helm, Kubernetes, Kustomize, OpenTofu, Prometheus, Grafana, DefectDojo, SonarQube, and Linux.
Coverage table
| Tool | Notes | Docs | Scripts | Configs | Snippets | Templates | Manifests | Dockerfiles | Notebooks | Policies | Last verified | Total |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| trufflehog | 3 | 2 | 3 | 2 | 2 | 21 | 1 | 1 | 2 | 0 | 2026-05-27 | 37 |
| zap | 5 | 3 | 2 | 2 | 4 | 16 | 0 | 1 | 0 | 0 | 2026-07-20 | 33 |
| syft | 4 | 5 | 3 | 1 | 1 | 15 | 1 | 1 | 2 | 0 | 2026-05-30 | 33 |
| checkov | 4 | 5 | 2 | 2 | 4 | 10 | 2 | 0 | 2 | 1 | 2026-05-27 | 32 |
| trivy | 3 | 3 | 5 | 2 | 1 | 6 | 2 | 1 | 2 | 0 | 2026-05-26 | 25 |
| terraform | 3 | 1 | 4 | 4 | 1 | 0 | 0 | 0 | 0 | 0 | 2026-08-04 | 20 |
| semgrep | 3 | 5 | 3 | 1 | 2 | 0 | 2 | 2 | 2 | 0 | 2026-05-26 | 20 |
| grype | 4 | 1 | 8 | 1 | 2 | 0 | 2 | 1 | 1 | 0 | 2026-06-08 | 20 |
| terrascan | 5 | 1 | 2 | 1 | 2 | 6 | 1 | 0 | 0 | 0 | 2026-07-10 | 18 |
| falco | 4 | 2 | 3 | 3 | 1 | 0 | 0 | 0 | 0 | 0 | 2026-07-19 | 13 |
| codeql | 3 | 1 | 1 | 1 | 4 | 0 | 1 | 1 | 0 | 0 | 2026-06-14 | 12 |
| vault | 3 | 2 | 2 | 2 | 1 | 0 | 0 | 1 | 0 | 0 | 2026-06-15 | 11 |
| gitguardian | 4 | 1 | 2 | 2 | 2 | 0 | 0 | 0 | 0 | 0 | 2026-06-14 | 11 |
| dependabot | 7 | 0 | 1 | 3 | 0 | 0 | 0 | 0 | 0 | 0 | 2026-08-08 | 11 |
| snyk | 4 | 1 | 1 | 2 | 1 | 0 | 0 | 1 | 0 | 0 | 2026-06-14 | 10 |
| opa | 3 | 1 | 1 | 1 | 3 | 0 | 0 | 0 | 0 | 0 | 2026-06-15 | 9 |
| cosign | 4 | 0 | 2 | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 2026-06-22 | 9 |
| docker | 2 | 1 | 2 | 1 | 0 | 0 | 0 | 2 | 0 | 0 | 2026-07-12 | 8 |
| argocd | 6 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | 0 | 0 | 2026-08-12 | 8 |
| github-actions | 3 | 0 | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 2026-08-04 | 7 |
| tetragon | 3 | 0 | 1 | 2 | 0 | 0 | 0 | 0 | 0 | 0 | 2026-08-06 | 6 |
| git | 3 | 0 | 2 | 0 | 1 | 0 | 0 | 0 | 0 | 0 | 2026-07-12 | 6 |
| sonarqube | 2 | 0 | 0 | 0 | 1 | 0 | 0 | 0 | 0 | 0 | 2026-07-19 | 3 |
| opentofu | 2 | 0 | 0 | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 2026-07-20 | 3 |
| kustomize | 2 | 0 | 0 | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 2026-07-08 | 3 |
| kubernetes | 2 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | 0 | 0 | 2026-07-15 | 3 |
| helm | 2 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | 0 | 0 | 2026-07-19 | 3 |
| defectdojo | 2 | 0 | 0 | 0 | 1 | 0 | 0 | 0 | 0 | 0 | 2026-08-04 | 3 |
| linux | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 2026-08-06 | 2 |
| ansible | 0 | 0 | 2 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | — | 2 |
| prometheus | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | — | 1 |
| grafana | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | — | 1 |
Foundational concept primers and practice exercises are complete across the toolchain, and per-tool quickstarts are being rounded out. Recent additions cover the Syft output format comparison notebook, a Syft + Trivy Kubernetes scan scaffold, ArgoCD GitOps sync setup, and further Terraform module composition patterns. Current focus is rounding out the remaining tool notes and expanding cross-tool integration scaffolds.
Last updated: 2026-08-15