
security-code-scan
Vulnerability Patterns Detector for C# and VB.NET

Vulnerability Patterns Detector for C# and VB.NET

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

A static code analysis for WordPress (and PHP)

RIPS - A static source code analyser for vulnerabilities in PHP scripts

👮 👊 RegEx Denial of Service (ReDos) Scanner

find hardcoded strings from source code

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…


Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Language server for YARA rule development, providing code completion, linting, formatting, navigation, and debugging support inside IDEs.

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…


jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.
