
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…


CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Vulnerability Assessment Scanner with Report Generation


The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

CLI tool to scan codebases for quantum-vulnerable cryptography