
kics
Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Vulnerability Assessment Scanner with Report Generation

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

A static analysis tool for securing Go code

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Open-source, cross-platform, multi-purpose security auditing tool

Static code analysis tool based on Elasticsearch

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.