
gitleaks
Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Fast and accurate AI powered file content types detection

A static analyzer for Java, C, C++, and Objective-C

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Tool to look for several security related Android application vulnerabilities

Zero shot vulnerability discovery using LLMs

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Security-focused static analysis for the Phoenix Framework

Pluggable linting tool to prevent committing credential.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

A fork of JSONPath from http://goessner.net/articles/JsonPath/

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…