
codeql
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…


jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512

扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

👮 👊 RegEx Denial of Service (ReDos) Scanner

Octoscan is a static vulnerability scanner for GitHub action workflows.

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

A Bitbucket Pipe to trigger SonarCloud analysis

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.
