
semgrep-rules
Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

python dependency vulnerability scanner, written in Rust.

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

Purple Team Exercise Framework

Filesystem scanner for Log4Shell (CVE-2021-44228) and related CVEs. Detects vulnerable JAR files via hash matching and class presence. Runs…

Performing security tests inside your CI

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

nodejsscan is a static security code scanner for Node.js applications.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

A static analyzer for Java, C, C++, and Objective-C

An enterprise friendly way of detecting and preventing secrets in code.

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Automatic security vulnerability remediation for your code.

CLI tool for the Horizon3.ai API