
ApplicationInspector
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

An enterprise friendly way of detecting and preventing secrets in code.

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

Chaos testing, network emulation, and stress testing tool for containers

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

Open-source vulnerability scanner with automated network discovery, CVE-based detection, CVSS scoring, risk dashboards, remote agents via gRPC, and a…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.