
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

agent runtime security - zero trust, zero setup, zero latency agent sandbox

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Open-source, cross-platform, multi-purpose security auditing tool

KQL injection in adx-mcp-server via table_name — CVE-2026-33980 / CVSS 8.3

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Open-source secret scanner in Rust

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities