
talisman
Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Draw.io libraries for threat modeling diagrams

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

Integration of Clair and Docker Registry

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)

Generate firewall ACLs for Cisco, Juniper, Palo Alto, and more from a single YAML policy language via CLI or Python API.

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Rust-powered HTTP Request Smuggling Scanner.

A simple file-based scanner to look for potential AWS access and secret keys in files

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Public OCI-Image (docker image) Security Checker