The Open-SourceDeveloper Security Platform

Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH

Dependency Proxy

Block threats before they reach your code.

DevGuard's dependency firewall sits between your builds and the public registries, so a package known to be malicious is refused on the way in rather than reported after the fact.

A control point in front of every install

Every npm, Go, PyPI and container image request is checked against the malicious package database first. Rules are plain text in gitignore syntax, scoped to an organisation, a project or a single repository.

237 726

malicious-package advisories every request is checked against, as of September 2026.

  • npm, Go, PyPI and OCI container images through one gateway
  • Blocked installs return HTTP 403, naming the advisory
  • Helps blocking attacks like the 2025 Shai-Hulud npm worm

VEX & Assessment Sharing

Software Security as Community Effort

Multi-level VEX handling, automated reachability analysis, and crowdsourced assessments - DevGuard eliminates false positives so you can focus on real risks.

Multi-Level VEX Handling

Share assessments to your consumers and receive from your suppliers. DevGuard supports full VEX lifecycle management - from initial triage to final justification.

Crowdsourced VEX-Rules

Started mid 2026: Users share anonymized assessment results as reusable VEX-Rules. Benefit from the collective knowledge of the community to reduce handling effort even further.

Coming Soon

Automated Vexing for npm

Coming 2026: Reachability analysis for the npm ecosystem that handles up to 70% of findings automatically. DevGuard determines whether vulnerable code paths are actually reachable.

The Reichstag, seat of the German parliament, on the bank of the Spree river in Berlin
640+

projects on openCode used DevGuard as of August 2026.

Public Sector

In production across German public administration

DevGuard secures the software supply chain of openCode, the open-source platform of German public administration - with vulnerability management, software bills of materials and evidence that holds up in an audit.

  • A software bill of materials for every build
  • Evidence for Cyber Resilience Act and BSI reporting obligations
  • Self-hosted and open source - no vendor lock-in
In production at
openCodeZenDiS

Testimonials

Trusted by Security-Focused Teams.

Julian Schauder
DevGuard schafft es durch moderne Software-Security-Konzepte unseren Entwicklern und Nutzern auf openCode einen benutzerfreundlichen Einstieg in die Best Practices des Schwachstellenmanagements zu ermöglichen, ohne dabei Abstriche in der Enterprisefähigkeit zu machen.

Julian Schauder

DevSecOps & Development Lead @ ZenDiS GmbH

Pricing

Secure Software Development &
Pricing made easy

Protect your code with confidence - DevGuard simplifies secure software development while offering flexible pricing tailored to your needs.

Start your 14-day free trial

Open Source

Fully-fledged self-hosting solution with community support. Free of charge for every FLOSS project. Get SaaS free as non-commercial FLOSS project.

Lifetime
Free
for public projects with OSI approved license

What's included

All features included
Community Support
Self Hosted
Request for hosted solution

Business SaaS

The carefree package, ideal for organizations that want to get started quickly with a high-performance service.

10User seats
101000
Starting at
€449.10/ month
1 year contract, paid yearly

What's included

4 hours monthly support included (a 10 seats)
Fully managed DevGuard hosted in Germany 🇩🇪
Sovereign open source software from Europe 🇪🇺
10 users included
Initial 1-hour setup workshop
8×5 E-Mail Support Hours

Enterprise

With SLA and support options for operation in your infrastructure. Ideal for large organizations or the security domain.

Starting at
Custom
Contact us for a custom quote

What's included

DevGuard in your data center or cloud
Sovereign open source software from Europe 🇪🇺
Unlimited users, projects & assets
Custom maintenance contract
Custom support & training
Custom SLA
Phone & Chat support
Customization for special requirements
Help with setting up the infrastructure

Screenshots

Everybody loves a good screenshot...

Dependency Risks
Dependency Risks

Start securing your applications in minutes, not months.

DevGuard allows you to start securing your applications in minutes. No complex setup, no code changes, just instant visibility and protection.

Thanks to everyone who contributed to DevGuard, whether through code, ideas, issue reports, or simply by being part of our community. We see you and we appreciate you!

Backend Core Contributor
Backend Contributor
Frontend Core Contributor
Frontend Contributor
Shaping the project

Made with ♥ in Germany 🇩🇪 for Europe 🇪🇺