
codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Static code analysis tool based on Elasticsearch

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

👮 👊 RegEx Denial of Service (ReDos) Scanner

jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512


Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.


Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…