
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

find hardcoded strings from source code

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange…

Fast and accurate AI powered file content types detection

A static analyzer for Java, C, C++, and Objective-C

PHP Static Analysis Tool - discover bugs in your code without running it!

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Bandit is a tool designed to find common security issues in Python code.

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Zero shot vulnerability discovery using LLMs

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications