
gitleaks
Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

find hardcoded strings from source code

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

A static analysis tool for securing Go code

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Pluggable linting tool to prevent committing credential.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Identify hardcoded secrets in static structured text

a guard that blocks catastrophic agent actions

A project security/vulnerability/risk scanning tool