
zizmor
Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

A tool for secrets management, encryption as a service, and privileged access management

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Secure agents in seconds with permissions enforced at runtime.

A vulnerability scanner for container images and filesystems

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Pluggable linting tool to prevent committing credential.

Simple and flexible tool for managing secrets

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Local-first password manager with direct device-to-device sync

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

Invisible infrastructure for Dracon developer workspaces: git sync, system guard, and warden encryption utilities.

Find and redact secrets in AI coding agent histories (Claude Code, and more).

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)