
infer
A static analyzer for Java, C, C++, and Objective-C

A static analyzer for Java, C, C++, and Objective-C

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

ProjectDiscovery's Open Source Tool Manager

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

A simple file-based scanner to look for potential AWS access and secret keys in files

A modern git based age-encrypted secrets manager for teams.

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Identify hardcoded secrets in static structured text

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…