
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Open-source secret scanner in Rust

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Security Governance for Agentic AI

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Scan codebases and GCP projects for exposed API credentials


Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Kubernetes RBAC static analysis & visualisation tool