
sast-rules
Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

client-side prototype pullution vulnerability scanner

The Secure Coding Practices Quick-reference Guide from OWASP

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Go static analysis tool that checks for security issues using an AST.


Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool


Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

CLI tool to scan codebases for quantum-vulnerable cryptography

CVE-2026-39259

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

解决网络安全漏洞

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…