
sonarqube
Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…


Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A static analysis tool for securing Go code

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Linting tool for CloudFormation templates

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Open-source, cross-platform, multi-purpose security auditing tool

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…