
XcInspector
A macOS app to scan Xcode project files for possible security issues.

A macOS app to scan Xcode project files for possible security issues.

Sandbox and MCP proxy that blocks AI coding agents from reading SSH keys, AWS credentials, and .env files, with deny-by-default policy and…

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Script to audit GitHub Action Workflow files for potential vulnerabilities.

VisualCodeGrepper - Code security scanning tool.

Scans Infrastructure as Code files for security misconfigurations and vulnerabilities using KICS, with Bitbucket Code Insights reporting.

Scans Git repositories for hardcoded secrets, keys, and passwords using Gitleaks, integrating security into Bitbucket Pipelines with Code Insights…

AWS Testing and Reporting Management Tool

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

A lightweight orchestrator and worker scanner setup for running large/continuous scans across split input files. This repository contains…

Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell

An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046

Harden your package manager configs against supply chain attacks.