
semgrep-rules
Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

A static analysis tool for securing Go code

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Open-source, cross-platform, multi-purpose security auditing tool

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Static code analysis tool based on Elasticsearch

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Vulnerability Assessment Scanner with Report Generation