
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

safe execution paths for agents - zero trust, zero setup, zero latency.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…


Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Security Governance for Agentic AI

Kubernetes RBAC static analysis & visualisation tool

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…