
jackhammer
Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

a static analysis tool for finding vulnerabilities in C/C++ source code

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Defense Against the Shai-Hulud Supply Chain Attack

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…


All-in-one tool for managing vulnerability reports from AppSec pipelines

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.