
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Hunt for AI coding artifacts containing secrets.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Open source compliance tool for development platforms.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Open-source, cross-platform, multi-purpose security auditing tool

A simple file-based scanner to look for potential AWS access and secret keys in files