
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…

A static analyzer for Java, C, C++, and Objective-C

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Link sources to sinks in C# applications.

Lightweight Protocol Buffers implementation in ANSI C for microcontrollers and memory-restricted embedded systems, enabling efficient serialization…

C++ library for detecting cross-site scripting (XSS) vulnerabilities in URLs through pattern analysis, with server modules and command-line tools for…

C library for parsing, editing, and saving EXIF data, patched for CVE-2020-0181 to prevent heap buffer overflow in EXIF tag parsing.

Reimplementation of CVE-2017-15361 checker in C

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

C library for stream-oriented XML parsing, providing handlers for parsing structures in documents. Includes xmlwf tool and supports UTF-16 encoding.

C library for parsing, editing, and saving EXIF data, with a focus on addressing CVE-2020-0452 in AOSP10. Provides API for metadata extraction and…

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

C library for parsing, editing, and saving EXIF metadata, with a focus on addressing CVE-2020-0198 in AOSP10.

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

Interactive program analysis suite using Code Property Graphs to hunt for bugs in C and C++ code, unifying application-specific and low-level…