24 projects
Harbor
Harbor is an open source container image registry that secures images with role-based access control, scans images for vulnerabilities, and signs images as trusted.
9,151
2,130
$41M
OSS-Fuzz
OSS-Fuzz is a continuous fuzzing infrastructure that helps identify security vulnerabilities in open source software through automated testing. It provides tools, infrastructure, and processes to make fuzzing an integral part of the development workflow for open source projects.
2,914
845
$6.8M
CodeQL
CodeQL is a semantic code analysis engine that helps developers and security researchers discover vulnerabilities across codebases. It treats code as data, allowing users to write queries to analyze codebases and find security weaknesses, bugs, and quality issues.
2,328
521
$87M
Semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
1,629
436
$36M
Gitleaks
Gitleaks is a security scanning tool that detects and prevents hardcoded secrets, credentials, and sensitive information in git repositories. It uses pattern matching and entropy analysis to identify potential data leaks in commit history and source code.
1,505
384
$829K
Brakeman
A static analysis security vulnerability scanner for Ruby on Rails applications
1,053
402
$2.2M
Lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
1,036
186
$828K

Grype
Grype is a vulnerability scanner for container images and filesystems that identifies known vulnerabilities in packages and dependencies across multiple programming languages and package managers.
961
273
$3.3M
Bandit
Bandit is a tool designed to find common security issues in Python code.
914
318
$747K
gosec
Go security checker
778
300
$872K
KICS
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
715
116
$34M
Trivy Action
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
598
196
$65K
SVF
Static Value-Flow Analysis Framework for Source Code
520
72
$2.5M
Maester
Maester is a PowerShell based test automation framework to help you stay in control of your Microsoft security configuration.
440
28
$5.4M
Retire.js
Retire.js is a security scanner that helps detect the use of JavaScript libraries with known vulnerabilities in web applications and Node.js projects. It analyzes JavaScript files and dependencies to identify outdated versions that may pose security risks.
427
120
$3M
OWASP Dependency-Check
OWASP Dependency-Check is a Software Composition Analysis (SCA) tool that detects publicly disclosed vulnerabilities in project dependencies. It scans application dependencies and identifies known security vulnerabilities by checking them against the National Vulnerability Database (NVD) and other data sources.
376
56
$6.8M
OWASP secureCodeBox
secureCodeBox (SCB) - continuous secure delivery out of the box
306
45
$14M
GitGuardian Secrets Detection and Infrastructure Security
Find and fix 400+ types of hardcoded secrets and 70+ types of infrastructure-as-code misconfigurations.
Joern
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Snyk CLI
Snyk CLI scans and monitors your projects for security vulnerabilities.
The OWASP ZAP Project
ZAP Add-ons