
gitleaks
Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Simple and flexible tool for managing secrets

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

An open source threat modeling tool from OWASP

Chaos testing, network emulation, and stress testing tool for containers

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Pluggable linting tool to prevent committing credential.

A tool to capture all the git secrets by leveraging multiple open source git searching tools

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

A powerful testing tool for Kubernetes clusters.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Linting tool for CloudFormation templates

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.