
RiskAssessmentFramework
OWASP Static Application Security Testing (SAST) tool for analyzing code quality and vulnerabilities, designed for DevSecOps integration to help…

OWASP Static Application Security Testing (SAST) tool for analyzing code quality and vulnerabilities, designed for DevSecOps integration to help…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

A vulnerability scanner for container images and filesystems

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Ansible Playbook for CVE-2023-36845(Juniper Networks Junos OS 远程代码执行漏洞)

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Checklist of the most important security countermeasures when designing, testing, and releasing your API

The easiest, and most secure way to access and protect all of your infrastructure.

A static analyzer for Java, C, C++, and Objective-C

AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool that inspects Go source code for security vulnerabilities using AST, SSA, and taint analysis, with CI/CD integration and CWE…


OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.