DevGuard
The open-source developer security platform for vulnerability management and securing the software supply chain.
DevGuard is an open-source platform for vulnerability and supply chain security that integrates security checks into the existing development workflow. Results appear right where developers work anyway: in merge requests, the CI/CD pipeline, and the issue tracker—rather than in separate tools or Excel spreadsheets. On openCode, DevGuard forms the technical core of the platform’s security suite and is available to all users (devguard.opencode.de) free of charge . Through the integration directly built into openCode, DevGuard performs automated security analyses and is used for projects requiring professional software security. This includes openDesk, the office and collaboration suite for public administration, whose software supply chain is secured and documented using DevGuard.
Instead of treating each finding based solely on its CVSS score, DevGuard weights findings multidimensionally: based on exploitability (EPSS), the depth of the affected dependency in the dependency tree, and the risk assessment for the respective project. This allows the truly relevant risks to be addressed first and reduces the testing effort for non-critical findings.
Through a single CLI and CI integration, DevGuard covers Software Composition Analysis (SCA), Static Application Security Testing (SAST), secret scanning, Infrastructure-as-Code scanning, container scanning, and license compliance. SBOMs and VEX reports are automatically generated and kept up to date. The platform integrates with GitLab and GitHub and supports attestation-based, traceable documentation in accordance with common security frameworks such as ISO 27001 and BSI IT-Grundschutz.
DevGuard is an OWASP Incubating Project and can be operated as SaaS or self-hosted. Development and maintenance are handled by L3montree Cybersecurity GmbH, based in Bonn.
Software-Details
08/25/26
09/04/26
stable
- web
- linux
1.13.2
AGPL-3.0-or-later
Making software use visible!
Last updated: