
octoscan
Octoscan is a static vulnerability scanner for GitHub action workflows.

Octoscan is a static vulnerability scanner for GitHub action workflows.

safe execution paths for agents - zero trust, zero setup, zero latency.

Prevents you from committing secrets and credentials into git repositories


OpenSSF Scorecard - Security health metrics for Open Source

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Automated PHP configuration auditor that scans php.ini for security misconfigurations, supports CLI and web modes, and outputs results in text, HTML,…

Kubernetes RBAC static analysis & visualisation tool

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Identify hardcoded secrets in static structured text

a guard that blocks catastrophic agent actions

Open-source, cross-platform, multi-purpose security auditing tool

Open source compliance tool for development platforms.

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing