
SecretScrub
Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

Processes SARIF output from static analysis tools to detect and redact hard-coded secrets in source code, creating a clean copy without the original…

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

AI-powered bug bounty hunting toolkit that works with or without subscription.

A Bitbucket Pipe to trigger SonarCloud analysis

Static code analysis tool based on Elasticsearch

CLI tool to scan codebases for quantum-vulnerable cryptography

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

PHP Static Analysis Tool - discover bugs in your code without running it!

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

A security scanner for your LLM agentic workflows

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…