
codeql
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

PHP Static Analysis Tool - discover bugs in your code without running it!

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Security risk analysis for Kubernetes resources

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

An extensible multilanguage static code analyzer.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Agentic AI security scanner that reasons like an attacker over source code, confirms exploitable flaws with executable PoCs, and drives test-first…