
codeql
Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

Static analysis tool that inspects Go source code for security vulnerabilities using AST, SSA, and taint analysis, with CI/CD integration and CWE…

A static analyzer for Java, C, C++, and Objective-C

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

AI-powered static code analysis tool (CLI + SDK) for discovering security vulnerabilities, validating findings, and generating patches. Supports…

PHP Static Analysis Tool - discover bugs in your code without running it!

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Multi-language SAST tool that scans source code, Git history, and IaC for security flaws, secrets, and misconfigurations, integrating into CI/CD…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

AST-based security linter that scans Python code for common vulnerabilities by running plugins against parsed syntax trees, generating detailed…

Static code analysis tool for Kubernetes object definitions that scores YAML/Helm charts for security, reliability, and best practices, with CI/CD…

a static analysis tool for finding vulnerabilities in C/C++ source code

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…