
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Ansible Playbook for CVE-2023-36845(Juniper Networks Junos OS 远程代码执行漏洞)

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Source code security scanner for expert code review; emits file:line findings in plain text, designed for fast manual triage and filtering with…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Automated security audit wrapper for .NET binaries: runs CAT.NET static analysis on all .NET binaries in a folder and tracks findings in a database.

👮 👊 RegEx Denial of Service (ReDos) Scanner

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

The easiest, and most secure way to access and protect all of your infrastructure.

AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

Runtime-aware SCA tool that proves reachability of CVEs via static analysis, taint tracking, and runtime coverage, enabling prioritized vulnerability…