
codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Static code analysis tool based on Elasticsearch

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…


Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

👮 👊 RegEx Denial of Service (ReDos) Scanner

jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512

The Secure Coding Framework


Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…