
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
API key scanning, credential leak detection, and secret management tools.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Prevents you from committing secrets and credentials into git repositories

Incredibly fast crawler designed for OSINT.

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Transparent file encryption in git

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Scanning APK file for URIs, endpoints & secrets.

Reconnaissance tool for GitHub organizations

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Snyk CLI scans and monitors your projects for security vulnerabilities.

OpenSSF Scorecard - Security health metrics for Open Source

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Open Source Cloud Native Application Protection Platform (CNAPP)

An enterprise friendly way of detecting and preventing secrets in code.