
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

find hardcoded strings from source code

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Sourcetrail - free and open-source interactive source explorer

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A static analyzer for Java, C, C++, and Objective-C

PHP Static Analysis Tool - discover bugs in your code without running it!

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Bandit is a tool designed to find common security issues in Python code.

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

OSWE, OSEP, OSED, OSEE

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…


Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.