
sshconfig-lint
Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

CVE-2026-42533 Nginx

All-in-one tool for managing vulnerability reports from AppSec pipelines

OpenSSF Scorecard - Security health metrics for Open Source

Prevents you from committing secrets and credentials into git repositories

Octoscan is a static vulnerability scanner for GitHub action workflows.

Managing GitHub Advanced Security (GHAS) Controls at Scale

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Anteater - CI/CD Gate Check Framework

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

VisualCodeGrepper - Code security scanning tool.

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…


Validate environment variable usage in codebase

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively