
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

Security risk analysis for Kubernetes resources

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

VisualCodeGrepper - Code security scanning tool.

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Scans Git repositories for hardcoded secrets, keys, and passwords using Gitleaks, integrating security into Bitbucket Pipelines with Code Insights…


Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Java source code generator that creates calling classes for Oracle PL/SQL package procedures, supporting various parameter types and automatic type…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…