The Open-SourceDeveloper Security Platform

Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität GießenIkorHeyloginopenCodeOWASPopenDeskSUSECronnCPSWhereGroupWetteronlineVerwaltungscloud.shBusinesscodeBCGReadyLabs GmbH

Dependency Proxy

Block threats before they reach your code.

DevGuard's dependency firewall sits between your builds and the public registries, so a package known to be malicious is refused on the way in rather than reported after the fact.

A control point in front of every install

Every npm, Go, PyPI, Maven, Composer and container image request is checked against the malicious package database first. Rules are plain text in gitignore syntax, scoped to an organisation, a project or a single repository.

237 726

malicious-package advisories every request is checked against, as of September 2026.

  • npm, Go, PyPI, Maven, Composer and OCI images through one gateway
  • Blocked installs return HTTP 403, naming the advisory
  • Helps blocking attacks like the 2025 Shai-Hulud npm worm

VEX & Assessment Sharing

Software Security as Community Effort

Multi-level VEX handling, automated reachability analysis, and crowdsourced assessments - DevGuard eliminates false positives so you can focus on real risks.

Multi-Level VEX Handling

Share assessments to your consumers and receive from your suppliers. DevGuard supports full VEX lifecycle management - from initial triage to final justification.

Crowdsourced VEX-Rules

Started mid 2026: Users share anonymized assessment results as reusable VEX-Rules. Benefit from the collective knowledge of the community to reduce handling effort even further.

Coming Soon

Automated Vexing for npm

Coming 2026: Reachability analysis for the npm ecosystem that handles up to 70% of findings automatically. DevGuard determines whether vulnerable code paths are actually reachable.

The Reichstag, seat of the German parliament, on the bank of the Spree river in Berlin
640+

projects on openCode used DevGuard as of August 2026.

Public Sector

In production across German public administration

DevGuard secures the software supply chain of openCode, the open-source platform of German public administration - with vulnerability management, software bills of materials and evidence that holds up in an audit.

  • A software bill of materials for every build
  • Evidence for Cyber Resilience Act and BSI reporting obligations
  • Self-hosted and open source - no vendor lock-in
In production at
openCodeZenDiS

Testimonials

Trusted by Security-Focused Teams.

Julian Schauder
“DevGuard schafft es durch moderne Software-Security-Konzepte unseren Entwicklern und Nutzern auf openCode einen benutzerfreundlichen Einstieg in die Best Practices des Schwachstellenmanagements zu ermöglichen, ohne dabei Abstriche in der Enterprisefähigkeit zu machen.”

Julian Schauder

DevSecOps & Development Lead @ ZenDiS GmbH

Pricing

Secure Software Development &
Pricing made easy

Protect your code with confidence - DevGuard simplifies secure software development while offering flexible pricing tailored to your needs.

Start your 14-day free trial

Open Source

Fully-fledged self-hosting solution with community support. Free of charge for every FLOSS project. Get SaaS free as non-commercial FLOSS project.

Lifetime
Free
for public projects with OSI approved license

What's included

All features included
Community Support
Self Hosted
Request for hosted solution

SaaS

The carefree package, ideal for organizations that want to get started quickly with a high-performance service.

10User seats
101000
Starting at
€449.10/ month
1 year contract, paid yearly

What's included

Fully managed DevGuard hosted in Germany 🇩🇪
Sovereign open source software from Europe 🇪🇺
10 users included
Initial 1-hour setup workshop
8×5 E-Mail Support Hours
Recommended

Enterprise

Self-hosting with an enterprise contract: contractual response times, vetted updates from the publisher and a fixed contract partner.

Annual subscription
On request
Plus one-time initial setup

What's included

Self-hosted in your data center - platform and data stay with you
Initial setup: Helm deployment, CI/CD, SSO/OIDC and onboarding
Contractual response times of 16 h, 8 h or 4 h
20 to 160 support hours per year
Maintenance with vetted updates from the publisher
Dedicated email, plus chat and phone from Advanced
Reproducible images with SBOM and VEX per release
Sovereign open source software from Europe 🇪🇺
or book an introduction call

Screenshots

Everybody loves a good screenshot...

Dependency Risks
Dependency Risks

Open Source

Committed to open source, in code and beyond.

DevGuard is developed in the open under AGPL-3.0 and built entirely on open standards. It stands on the shoulders of countless open-source projects, and we are deeply grateful to the maintainers who keep them going.

Proud member of

  • The Linux Foundation
  • OpenSSF
  • Open Source Business Alliance

Thank you to our contributors

DevGuard is shaped by everyone who contributes - through code, ideas, issue reports or simply by being part of our community. We see you and we appreciate you.

Meet the contributors

Start securing your applications in minutes, not months.

DevGuard allows you to start securing your applications in minutes. No complex setup, no code changes, just instant visibility and protection.