
bandit
Bandit is a tool designed to find common security issues in Python code.

Bandit is a tool designed to find common security issues in Python code.

find hardcoded strings from source code

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

A static code analysis for WordPress (and PHP)

PHP Static Analysis Tool - discover bugs in your code without running it!

A security scanner for your LLM agentic workflows

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

The Secure Coding Framework