
SecretScrub
Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

Community-owned database of security advisories for Python packages on PyPI, providing structured vulnerability data in OSV format for integration…

Easy setup of static analysis tools for Android and Java projects.

Trail of Bits Testing Handbook - appsec.guide

The Secure Coding Framework

Finding exposed secrets and personal data in GitLab

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA

CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local development, and multi-language…

A tool for secrets management, encryption as a service, and privileged access management

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Find, verify, and analyze leaked credentials

Infisical is the open-source platform for secrets, certificates, and privileged access management.

The easiest, and most secure way to access and protect all of your infrastructure.

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

A static analyzer for Java, C, C++, and Objective-C