
infer
A static analyzer for Java, C, C++, and Objective-C

A static analyzer for Java, C, C++, and Objective-C

Static source code analyzer that identifies software features, APIs, and security characteristics using 400+ regex-based rules. Helps determine what…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

A portable Bash script to detect vulnerable versions of React Server DOM and Next.js packages affected by [CVE-2025-55182]

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Static security code scanner (SAST) for Node.js applications, powered by libsast and semgrep, with CLI, web UI, and CI/CD integrations for automated…

a static analysis tool for finding vulnerabilities in C/C++ source code

A source code static analysis platform for AppSec enthusiasts.

Scans local projects for CVE-2025-66478 vulnerability and reports affected instances without fixing them.

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

A Bitbucket Pipe to trigger SonarCloud analysis

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

A static analysis security vulnerability scanner for Ruby on Rails applications

Audit Rust crate dependencies against the RustSec Advisory Database. CI/CD-friendly CLI for automated vulnerability scanning of Cargo.lock.

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…