
bearer
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…


Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

Vulnerability Assessment Scanner with Report Generation

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…