

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

A security scanner for your LLM agentic workflows

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

The Secure Coding Framework

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

nodejsscan is a static security code scanner for Node.js applications.

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

A static analyzer for Java, C, C++, and Objective-C

A static analysis tool for securing Go code

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…