A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Fast local security scanning for code, secrets, dependencies, and crypto risk.
Integrated into 0sec, the open cybersecurity harness.
npx foxguard .
npx foxguard . # zero install
curl -fsSL https://foxguard.dev/install.sh | sh # prebuilt binary (macOS/Linux)
cargo install foxguard # from source
Prebuilt installs verify release binaries against checksums.txt. Release binaries also publish GitHub artifact attestations; use gh attestation verify for manual verification, or see release provenance.
GitHub Action:
- uses: 0sec-labs/foxguard/[email protected]
with:
path: .
severity: medium
fail-on-findings: "true"
upload-sarif: "true"
pre-commit:
repos:
- repo: https://github.com/0sec-labs/foxguard
rev: v0.13.0
hooks:
- id: foxguard
Integrations: GitHub App, VS Code, Claude Code plugin, and MCP server.
foxguard-github-app writes newline-delimited JSON logs. Completed and failed
scans use event=foxguard.scan.completed and event=foxguard.scan.failed, with
delivery, installation, repository, PR, commit, duration, and usage_scope
fields for correlation. Keep identifiers as log fields, not metric labels.
Set FOXGUARD_INTERNAL_ACCOUNTS to a comma-separated list of your own GitHub
accounts and organizations. Matching is case-insensitive. Other owners are
classified as external; an unset list or missing owner produces unknown.
External activity is not proof of a paying customer, and scans are not people.
The installation registry is reconciled against all pages of GitHub's App installation API at startup and hourly. Failed refreshes retain existing state; concurrent webhooks take precedence. Sparse webhook metadata preserves known account details and observed repository names. Those names are not a complete inventory of an installation's accessible repositories.
Persist FOXGUARD_INSTALLATIONS_PATH and FOXGUARD_PULL_REQUEST_JOBS_PATH on
durable storage. Monitor foxguard.installations.reconcile_failed alongside
scan failures; foxguard.installations.reconciled reports the total and
internal/external/unknown installation counts after a successful refresh.
Size FOXGUARD_PR_WORKERS against measured scanner peak memory and the
container memory limit: child-process OOM kills can occur without restarting
the hosted application.
foxguard . # scan everything
foxguard diff main . # only new findings vs main
foxguard secrets . # leaked credentials and keys
foxguard sca . # dependency vulnerabilities from OSV
foxguard pqc . # post-quantum crypto audit
foxguard --format sarif . > results.sarif
foxguard --format semgrep-json . # Semgrep CLI-compatible JSON
Use foxguard --fix src/ or foxguard --fix src/app.py to apply supported taint
fixes in place. Targets are checked against the canonical scan directory or the
selected file; findings outside that scope are skipped. Python command-injection
fixes add import subprocess when needed, preserving module docstrings and future
imports. Review generated changes before committing.
| Language | Built-in rules | Taint tracking | Framework-aware rules |
|---|---|---|---|
| JavaScript / TypeScript | Yes | Yes | Express, Next.js |
| Python | Yes | Yes | Django, Flask, FastAPI |
| Go | Yes | Yes | Gin |
| Kotlin | Yes | Yes | Spring |
| Java | Yes | Yes | Spring |
| Ruby | Yes | Yes | Rails |
| PHP | Yes | Yes | Laravel |
| Rust | Yes | -- | -- |
| C# | Yes | Yes | .NET |
| Swift | Yes | Yes | iOS |
| Haskell | Yes | -- | Cardano seed rules |
Taint tracking also covers C, Bash, and Solidity. Config, manifest, and external-rule scans cover Dockerfile, Nginx, Apache, HAProxy, HCL/Terraform, YAML/JSON/XML/HTML, C via Semgrep YAML/Coccinelle, and more.
foxguard sca .
foxguard pqc .
foxguard --rules ./semgrep-rules .
SCA supports Cargo.lock, package-lock.json, pnpm-lock.yaml, requirements.txt, poetry.lock, and Pipfile.lock. The PQC audit is a two-sided scorecard: it flags quantum-vulnerable primitives (RSA, ECDSA/DSA, ECDH/DH) with CNSA 2.0 migration deadlines, and it also detects post-quantum algorithms already in use (ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, and hybrids like X25519MLKEM768) as informational, quantum-resistant inventory — reporting a migration-readiness percentage. Both sides export to a CycloneDX 1.6 CBOM, where post-quantum algorithms appear as quantum-resistant assets rather than vulnerabilities.
foxguard auto-discovers .foxguard.yml from the scan path upward.
scan:
baseline: .foxguard/baseline.json
disable_rules: [py/no-eval]
secrets:
exclude_paths: [fixtures, testdata]
Suppress an accepted finding inline with // foxguard: ignore[rule-id].
Start with the documentation index. Key references: architecture, Semgrep/OpenGrep compatibility, and the release runbook.
| Repo | LoC | foxguard | Semgrep | Speedup |
|---|---|---|---|---|
| express | 15K JS | 0.28s | 6.09s | 22x |
| flask | 14K Py | 0.33s | 6.51s | 20x |
| gin | 18K Go | 0.50s | 4.95s | 10x |
| sentry | 1.3M Py | 35s | 194s | 5x |
Reproduce with ./benchmarks/run.sh; results vary by machine. See benchmarks/README.md.
See CONTRIBUTING.md for rule authoring, tests, and development setup.
MIT OR Apache-2.0 -- 0sec Labs