
scodescanner
Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…


Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Verified tutorials and demo videos from your README. An AI agent runs it in a hardened Docker sandbox and replays it in a fresh container before…

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.


A benchmark for evaluating AI agents on fixing real-world security vulnerabilities.

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool



jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512

A small repo with a single playbook.

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…