Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/ffsshhttiikk/opencode-agents-skills --skill devsecops명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | devsecops |
| description | Security integration in DevOps practices |
| license | MIT |
| compatibility | opencode |
| metadata | {"audience":"developer, security-engineer, devops-engineer","category":"security"} |
stages:
- secret-scan
- dependency-scan
- static-analysis
- build-scan
- image-scan
- deploy-scan
secret-scan:
stage: secret-scan
script:
- gitlab-sast
allow_failure: false
dependency-scan:
stage: dependency-scan
script:
- npm audit --audit-level=high
- snyk test
- trivy fs --security-checks vuln
allow_failure: false
static-analysis:
stage: static-analysis
script:
- semgrep --config=auto --json .
- sonarqube-scanner
allow_failure: true
image-scan:
stage: image-scan
script:
- trivy image --severity HIGH,CRITICAL myapp:$CI_COMMIT_SHA
- dockle myapp:$CI_COMMIT_SHA
allow_failure: false
# OPA Gatekeeper policy
package kubernetes.admission
deny[msg] {
input.request.kind.kind == "Deployment"
not input.request.object.spec.template.spec.containers[_].securityContext.runAsNonRoot
msg = "Containers must run as non-root"
}
deny[msg] {
input.request.kind.kind == "Pod"
input.request.object.spec.containers[_].securityContext.privileged
msg = "Containers must not be privileged"
}
# CycloneDX in CI/CD
syft app:latest -o cyclonedx-json > sbom.json
# Trivy SBOM
trivy sbom app:latest --format cyclonedx
# SPDX
syft app:latest -o spdx-json
# HashiCorp Vault integration
apiVersion: v1
kind: Secret
metadata:
name: vault-secrets
type: Opaque
stringData:
secret.properties: |
DB_PASSWORD=$(vault kv get -field=password secret/database)
API_KEY=$(vault kv get -field=api_key secret/api)
| Language | Tools |
|---|---|
| Python | Bandit, Safety, Semgrep |
| Java | SpotBugs, SonarQube |
| JavaScript | ESLint, Semgrep |
| Go | Gosec, Staticcheck |
| All | Semgrep, SonarQube |
dast:
stage: dynamic-analysis
script:
- zap-baseline.py -t $STAGING_URL -r zap_report.html
- nuclei -u $STAGING_URL
allow_failure: true