All plugins
Meta plugin · Security

Security plugins for VibeControls

Security lifecycle orchestrator — dispatches every dev / pr / merge / build / release stage to the right per-stage security provider.

14 per-lifecycle-stage security providers — secrets, SAST, DAST, SBOM, scorecards, signing, runtime, release gates.

$vibe plugin install @vibecontrols/vibe-plugin-security
Security — VibeControls plugin illustration

14 providers

Each provider implements the Security contract for a specific backend. Install the meta plugin plus the provider(s) you need.

providerSecurity

Archive Offboard

Writes tombstone.json evidence at archive.offboard for SOC2/ISO retention proofs.

@vibecontrols/vibe-plugin-security-archive
providerSecurity

DAST (preview)

OWASP ZAP baseline DAST scan against alpha preview URLs at deploy.preview.

@vibecontrols/vibe-plugin-security-dast-preview
providerSecurity

Deploy alpha smoke

TLS / HSTS / CSP smoke checks for alpha environment URLs at deploy.alpha.

@vibecontrols/vibe-plugin-security-deploy-alpha
providerSecurity

Developer local

Local pre-commit secrets scanner (gitleaks protect) — runs on the developer machine.

@vibecontrols/vibe-plugin-security-developer-local
providerSecurity

Incident response

Targeted incident-response scanner for incident.response lifecycle stage.

@vibecontrols/vibe-plugin-security-incident
providerSecurity

Repo onboard

Repo profile detector — picks the right policy bundle on repo.onboard.

@vibecontrols/vibe-plugin-security-onboard
providerSecurity

Package publish

Cosign signing + SLSA provenance at package.publish.

@vibecontrols/vibe-plugin-security-package-publish
providerSecurity

Release gate

OPA-backed release-gate at promote.prod — block on policy, evidence-required deploys.

@vibecontrols/vibe-plugin-security-release-gate
providerSecurity

Scheduled rescan

Nightly Grype offline rescan against last-built SBOMs.

@vibecontrols/vibe-plugin-security-rescan
providerSecurity

Runtime continuous

Trivy + kube-bench continuous runtime checks against live workloads.

@vibecontrols/vibe-plugin-security-runtime
providerSecurity

SAST deep

Full SAST + SCA sweep (Semgrep + osv-scanner) on pull_request.deep.

@vibecontrols/vibe-plugin-security-sast-deep
providerSecurity

SBOM build

Syft CycloneDX SBOM + Grype scan at build lifecycle stage.

@vibecontrols/vibe-plugin-security-sbom-build
providerSecurity

OpenSSF Scorecard

OpenSSF Scorecard checks at main.merge — track posture over time.

@vibecontrols/vibe-plugin-security-scorecard
providerSecurity

Secrets (PR)

Gitleaks-backed secret scanner for pull_request.fast — fail fast on PR.

@vibecontrols/vibe-plugin-security-secrets-pr

We use cookies for essential site functions and, with your consent, for analytics to improve VibeControls. We don't use advertising or cross-site tracking cookies. See our Cookie Policy.

Preferences