---
title: "Four Tools That Support Your DevSecOps Process"
source: "https://www.tigera.io/blog/four-tools-that-support-your-devsecops-process/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Four Tools That Support Your DevSecOps Process

By [Daniel Oh](https://www.tigera.io/blog/author/daniel-oh/) on Dec 20, 2018 • 2 min read

Security is always the last phase of measuring your DevOps initiative’s success. Enterprises that have combined development and operations teams under a DevOps model are generally successful in releasing code at a much faster rate. But this has increased the need for integrating security in the DevOps process (this is known as DevSecOps), because the faster you release code, the faster you release any vulnerabilities in it.

## Open Source Security Tools

Measuring security vulnerabilities early ensures that builds are stable before they pass to the next stage in the release pipeline. In addition, measuring security can help overcome resistance to DevOps adoption. You need tools that can help your dev and ops teams identify and prioritize vulnerabilities as they are using software, and teams must ensure they don’t introduce vulnerabilities when making changes. These open source tools can help you measure security:

- [Gauntlt](http://gauntlt.org/) is a ruggedization framework that enables security testing by devs, ops, and security.

- [Vault](http://www.hashicorp.com/blog/vault.html) securely manages secrets and encrypts data in transit, including storing credentials and API keys and encrypting passwords for user signups.

- [Clair](http://github.com/coreos/clair) is a project for static analysis of vulnerabilities in appc and Docker containers.

- [SonarQube](http://www.sonarqube.org/) is a platform for continuous inspection of code quality. It performs automatic reviews with static analysis of code to detect bugs, code smells, and security vulnerabilities.

Many DevOps initiatives start small. DevOps requires a commitment to a new culture and process rather than new technologies. That’s why organizations looking to implement DevOps will likely need to adopt open source tools for collecting data and using it to optimize business success. In that case, highly visible, useful measurements will become an essential part of every DevOps initiative’s success

This article is originated from [http://opensource.com/article/18/10/devops-measurement-tools](http://opensource.com/article/18/10/devops-measurement-tools)

Daniel Oh is a Tigera guest blogger. He works as a DevOps evangelist with Senior Specialist Solution Architect and he takes the role of CNCF ambassador to encourage developers’ participation of cloud-native app development at scale and speed.

————————————————-

[**Free Online Training**](https://www.tigera.io/events/)

Access Live and On-Demand Kubernetes Tutorials

[**Calico Enterprise – Free Trial**](https://www.calicocloud.io/home)

Solve Common Kubernetes Roadblocks and Advance Your Enterprise Adoption

[Open Source](https://www.tigera.io/tags/open-source/)

## Related posts

[![What’s new in Calico: Spring 2026 Release](https://www.tigera.io/app/uploads/2026/06/Whats-New-in-Calico-NEW-TEMPLATE-2026.png)](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[Company Blog](https://www.tigera.io/category/company-blog/)

#### [What’s new in Calico: Spring 2026 Release](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on Jun 2, 2026

Kubernetes has come a long way since its debut in 2014. It’s gone from running a couple of containerized microservices to orchestrating fleets of production workloads spanning everything from AI agents to full scale VMs...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[![Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/app/uploads/2026/05/Kubernetes-Operational-Maturity-Secure-and-Resilient-Cluster-Federation-with-Cluster-Mesh.png)](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

#### [Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on May 25, 2026

Practically no one runs a single Kubernetes cluster in production these days. Maybe that’s how it started but data sovereignty requirements, acquisitions, AI initiatives and the need for edge servers, among other considerations, have pulled...

[Read more](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

[![What’s New in Calico v3.32](https://www.tigera.io/app/uploads/2026/05/Green-Please-use-a-different-background-color-alternately-1.png)](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

#### [What’s New in Calico v3.32](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

By [Reza Ramezanpour](https://www.tigera.io/blog/author/rezar/)
on May 13, 2026

We’re excited to announce the release of Calico Open Source v3.32! 🎉 This release corresponds with Kubernetes v1.36 (Codename Haru) and it goes beyond just sharing a cat as the mascot of the release, it...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6158 metric#misses=41 metric#hit-ratio=99.3 metric#bytes=2189243 metric#prefetches=0 metric#store-reads=421 metric#store-writes=35 metric#store-hits=407 metric#store-misses=30 metric#sql-queries=45 metric#ms-total=1167.82 metric#ms-cache=62.17 metric#ms-cache-avg=0.1366 metric#ms-cache-ratio=5.3 -->
