
codex-security
AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

A vulnerability scanner for container images and filesystems

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Static analysis tool that inspects Go source code for security vulnerabilities using AST, SSA, and taint analysis, with CI/CD integration and CWE…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Declarative DNS management tool with a JavaScript-compatible DSL for automating DNS record changes across 64+ providers, enabling GitOps workflows…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

A static analyzer for Java, C, C++, and Objective-C

Detects and mitigates CVE-2025-30749 RCE vulnerability in Oracle Java SE by scanning installed versions and flagging unpatched installations for…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

TrustedRouter.com repo for secure LLM proxying

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Pluggable linting tool to prevent committing credential.

A reverse proxy like nginx, built on pingora, simple and efficient.

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems