Know every component in operation.
Every build produces a software bill of materials, so the components behind a service are documented rather than assumed - including the dependencies no one selected deliberately.

projects on openCode used DevGuard as of August 2026.
Public administration has to account for the software it operates. DevGuard turns that obligation into an automated and auditable process - without introducing another proprietary dependency in the process.
Every build produces a software bill of materials, so the components behind a service are documented rather than assumed - including the dependencies no one selected deliberately.
Findings, decisions and justifications are recorded as the work happens, so reporting obligations and audits draw on a record that already exists instead of one assembled afterwards.
DevGuard is open source and built on open standards. It can be self-hosted, audited and extended by the administration itself, and the data never has to leave your own infrastructure.
Innovation
The capabilities below were developed together with public sector teams and are in production today. Each one builds on open standards, so results stay comparable and portable between administrations.
A live picture of which vulnerabilities affect which services, across every repository, container image and SBOM in the organisation.
Release criteria are defined against open standards and can be enforced in the pipeline, so a build that fails them does not reach production.
A dependency proxy screens packages before they reach a build, so known-vulnerable versions are stopped on the way in.
Obligations from the Cyber Resilience Act and the BSI technical guidelines are integrated to be tracked, with their status tracked per project over time.
A single installation serves hundreds of projects and teams, with tenancy, roles and reporting that follow how public administration is actually organised.
Findings from every project are consolidated and prioritised, so teams work through what is genuinely exploitable instead of a raw vulnerability count.
Success stories
DevGuard secures the software supply chain of the platform German public administration publishes its own open source on it.
openCode is the open-source platform of German public administration, operated by the Zentrum für Digitale Souveränität (ZenDiS) on behalf of the Federal Ministry for Digital Transformation and Government Modernisation (BMDS). DevGuard provides vulnerability management and software bills of materials for the projects hosted there.
DevGuard schafft es durch moderne Software-Security-Konzepte unseren Entwicklern und Nutzern auf openCode einen benutzerfreundlichen Einstieg in die Best Practices des Schwachstellenmanagements zu ermöglichen, ohne dabei Abstriche in der Enterprisefähigkeit zu machen.

The badge programme on openCode uses DevGuard to verify how projects handle their vulnerability management. It turns established practice into a visible, comparable signal — so administrations can judge at a glance whether a project is worth reusing.
Open the badge programmeOpen Source in der öffentlichen Verwaltung erfordert eine sichere und transparente Software-Lieferkette. L3montree hat uns durch Fachwissen und eine schnelle technische Umsetzung dabei unterstützt, unsere Software-Plattform openCode in diese Richtung weiterzuentwickeln.

Collaboration
The DevGuard maintainers work closely with ZenDiS and the BSI so the platform matches what public administration actually needs - from sovereign hosting to reporting and evidence.
Digital sovereignty
Public administration depends on software it can audit, rebuild and maintain itself. A verifiable software supply chain is what turns open source into long-term digital sovereignty - and that is exactly the layer DevGuard secures.
„Mit ‚DevGuard‘ wird Entwickelnden außerdem ein Tool an die Hand gegeben, das Sicherheits-Features direkt mit in die Entwicklung einfließen lässt.“