
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Snyk CLI scans and monitors your projects for security vulnerabilities.

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Prevents you from committing secrets and credentials into git repositories

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Performing security tests inside your CI

Cloud native secrets management for developers - never leave your command line for secrets.

A wrapper around grep, to help you grep for things

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…