
flawfinder
a static analysis tool for finding vulnerabilities in C/C++ source code

a static analysis tool for finding vulnerabilities in C/C++ source code


Vimana is an experimental security tool that aims to provide resources for auditing Python web applications.

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Defense Against the Shai-Hulud Supply Chain Attack


Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.


Static analysis of malicious Python code

All-in-one tool for managing vulnerability reports from AppSec pipelines

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations