OPEN SOURCE · EVENTS · LEARNING

A community you can check the receipts on

Everything below is something we publish, not something we promise. Repositories you can clone, a license and a maintenance status on every one of them, events with a published agenda, courses with a stated batch size, and a private route to report a vulnerability. Pick the one that fits and start there.

How to get involved

Six ways to take part

Each one names the mechanism and links to the page that carries the detail, so you can find the terms before you commit an afternoon.

Contribute to an open-source project

All 50 repositories in our catalogue are public and carry an OSI license. Each project page states the language, the license and the exact part we own, so you can pick a codebase you can actually read before you open a pull request.

Browse the catalogue

Attend an event

Summits, hands-on workshops and webinars, published with the agenda, the venue or the join link, and the registration fee, before registration opens. Hybrid sessions are recorded.

See what is scheduled

Take a cohort-based course

23 programmes, from full-stack development to DevSecOps and ethical hacking. Each one publishes its duration, its batch size and whether it runs live, hybrid or self-paced, so you can pick a format that fits your week.

List the courses

Apply for the internship

A three-month programme on live client projects, with a weekly one-to-one session with a senior engineer, an experience certificate at the end, and a pre-placement offer path into the engineering team.

Internship details

Join the team

10 roles are open right now across engineering, security, infrastructure and marketing. Salary band, location and employment type are listed on the role, not negotiated after you apply.

Open roles

Report a security issue

Found a vulnerability in something we build or maintain? Send it through the contact form and mark it as a security report so it does not land in a public issue tracker. We will acknowledge it and agree a fix window with you.

Report privately

Open source

50 public repositories, one license field

The catalogue is the argument. Every entry names its OSI license, its primary stack, its release status and the specific part DEV SEC IT owns, so you can verify a dependency before you adopt it.

Production

DSI VAPT Scanner

Python

License

MIT

A SAST and dependency-audit scanner that emits SARIF, so findings land in the same pipeline as lint.

2.1k stars · since 2022

Open project
Production

DSI Secrets Broker

Go

License

Apache-2.0

A sidecar that rotates secrets into running containers without a redeploy, using a KMS-backed lease per process.

1.4k stars · since 2023

Open project
Production

DSI SBOM CLI

Go

License

Apache-2.0

Generates CycloneDX and SPDX SBOMs from a container image or a lockfile, with a diff mode for release gates.

760 stars · since 2024

Open project
Production

DSI A11y Audit

TypeScript

License

MIT

Runs axe-core plus a keyboard-trap check and reports the failing selector, not just the rule name.

680 stars · since 2024

Open project
Production

DSI Contract Harness

TypeScript

License

Apache-2.0

Runs consumer-driven contract tests in CI against a provider stub, so a breaking change fails the build that introduced it.

1.1k stars · since 2023

Open project
Production

DSI Docgen

TypeScript

License

Apache-2.0

Reads an OpenAPI document and emits reference docs plus runnable examples in five languages, checked in CI so they cannot rot.

810 stars · since 2022

Open project
Production

DSI Data Grid

TypeScript

License

MIT

A virtualised grid for very large client datasets with server-side sort and a keyboard-first cell navigation model.

1.3k stars · since 2022

Open project
Production

DSI Audit Logger

Go

License

Apache-2.0

Tamper-evident audit logging for regulated workloads, with the hash chain exported in a format an auditor can verify offline.

590 stars · since 2023

Open project

Events

Sessions you can actually attend

Only dates that have not passed are listed here. When the calendar is empty we say so rather than showing a schedule that is out of date — every session we have run is recorded and published instead.

Nothing is on the calendar right now

Every event in the catalogue has already run, so we are not showing dates that would send you to a venue on a day that has gone. The recordings and the written material from past sessions are published, and the event page is where the next date appears first.

Ground rules

How we expect each other to behave

Four expectations that apply in the repositories, on the event calls and in the review threads. They are short on purpose — if something here is unclear, ask us before you act on it.

Open to anyone who wants to build

Students, career changers, working engineers and people reporting a vulnerability for the first time. The only baseline is that you treat the person on the other side of the thread as a colleague.

Ask before you assume

Issue threads and discussions are public and archived, so they are searchable for the next person with the same question. A question costs a maintainer a few minutes; a misdirected pull request costs everyone an afternoon.

Disclose before you disclose

Send a vulnerability to us privately before you file an issue or a pull request, and give us a reasonable window to ship a fix. Researchers who follow that sequence are credited, not prosecuted.

Review the code, not the person

Review comments address the diff and the reasoning behind it. Harassment, personal attacks and unsolicited promotion get removed, and repeating that ends access to the repositories and the events.

There is no signed legal document behind this section. It is the working agreement we apply, and the route to challenge it is the same as for anything else here: ask us directly.

Get involved

Start with the smallest useful step

Clone a repository and open an issue, or tell us what you are trying to build and we will point you at the engineer who has done it before. Either way you get a human answer.