
secretlint
Pluggable linting tool to prevent committing credential.

Pluggable linting tool to prevent committing credential.

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A hybrid security scanner for detecting CVE-2025-55182 in Next.js and Waku applications. Features combined static code analysis and safe dynamic…

Easy setup of static analysis tools for Android and Java projects.

A Public Package Scanner for The Community


A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

A static analysis security vulnerability scanner for Ruby on Rails applications

A source code static analysis platform for AppSec enthusiasts.

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Static code analysis tool based on Elasticsearch