
kics
Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

Open-source, cross-platform, multi-purpose security auditing tool

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Vulnerability Assessment Scanner with Report Generation

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

A static analysis tool for securing Go code

Static code analysis tool based on Elasticsearch