Skip to content

Entry

GuardRails

Appears in 4 awesome lists

A GitHub App that gives you instant security feedback in your Pull Requests.

Open github.comapps/guardrails

Found in these lists

Contents

Section: Multi tools · A GitHub App that gives you instant security feedback in your Pull Requests.

StaleScore 46

Awesome Security

Section: Development · A GitHub App that provides security feedback in Pull Requests.

SlowScore 70

Awesome Web Security

Section: Detecting · A GitHub App that provides security feedback in Pull Requests.

FreshScore 87

Awesome Nodejs

Section: Security · GitHub app that provides security feedback in pull requests.

FreshScore 90

Checkov

Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

In 7 listsDetails

Bearer

Open-Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.

In 6 listsDetails

KICS

Scans IaC projects for security vulnerabilities, compliance issues, and infrastructure misconfiguration. Currently working with Terraform projects, Kubernetes manifests, Dockerfiles, AWS CloudFormation Templates, and Ansible playbooks.

In 5 listsDetails

pompelmi

In-process file-upload security middleware for Node.js that scans untrusted uploads before storage to detect malware, MIME spoofing, and risky archives, maintained by pompelmi.

In 5 listsDetails

retire.js

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

In 3 lists

repo-supervisor

Auth0 - Secrets scanning tool that can run as a CLI, as a Docker container or in AWS Lambda.

In 3 lists

OpenRASP

An open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load.

In 3 lists

TFSec

Terraform static analysis tool that prevents potential security issues by checking cloud misconfigurations at build time and directly integrates with the HCL parser for better results. Checks for violations of AWS, Azure and GCP security best practice recommendations.

In 2 lists