
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Identify hardcoded secrets in static structured text

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Open source compliance tool for development platforms.

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Static analysis of malicious Python code

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Patched Vue 2.7.16 template compiler with fixes for CVE‑2024‑6783 and CVE-2024-9506