Contents
Section: Multi tools · A GitHub App that gives you instant security feedback in your Pull Requests.
Entry
Appears in 4 awesome lists
A GitHub App that gives you instant security feedback in your Pull Requests.
Section: Multi tools · A GitHub App that gives you instant security feedback in your Pull Requests.
Section: Development · A GitHub App that provides security feedback in Pull Requests.
Section: Detecting · A GitHub App that provides security feedback in Pull Requests.
Section: Security · GitHub app that provides security feedback in pull requests.
Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.
Open-Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.
Scans IaC projects for security vulnerabilities, compliance issues, and infrastructure misconfiguration. Currently working with Terraform projects, Kubernetes manifests, Dockerfiles, AWS CloudFormation Templates, and Ansible playbooks.
In-process file-upload security middleware for Node.js that scans untrusted uploads before storage to detect malware, MIME spoofing, and risky archives, maintained by pompelmi.
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
Auth0 - Secrets scanning tool that can run as a CLI, as a Docker container or in AWS Lambda.
An open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load.
Terraform static analysis tool that prevents potential security issues by checking cloud misconfigurations at build time and directly integrates with the HCL parser for better results. Checks for violations of AWS, Azure and GCP security best practice recommendations.