
regexploit
Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)


Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Bandit is a tool designed to find common security issues in Python code.

A CodeQL query to find CVE 2022-35737

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

find hardcoded strings from source code

grep rough audit - source code auditing tool

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security