
kube-score
Static code analysis tool for Kubernetes object definitions that scores YAML/Helm charts for security, reliability, and best practices, with CI/CD…

Static code analysis tool for Kubernetes object definitions that scores YAML/Helm charts for security, reliability, and best practices, with CI/CD…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

Static analysis tool that inspects Go source code for security vulnerabilities using AST, SSA, and taint analysis, with CI/CD integration and CWE…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Static analysis tool for Terraform code that detects potential security misconfigurations across major cloud providers, with hundreds of built-in…

a static analysis tool for finding vulnerabilities in C/C++ source code

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Static code analysis tool based on Elasticsearch

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…