Projects with this topic
-
Anura is an open-source harness platform built by the security research community to create an independent, realistic benchmark for AI systems used in security research. It runs models and agents against real public, authorized bug bounty scopes and security artifacts, then measures what they actually discover, validate, and reject in practical investigations.
Updated -
A post-processor for computing the scope+offset fingerprint.
UpdatedUpdated -
GitLab's semgrep container image augmented with hundreds of additional Node.js/JavaScript/Typescript and Go rules from Semgrep's rule repository.
Updated -
SAST Analyzer based on Semgrep
Updated -
Qualor CI/CD component: code quality and security scanning with a quality gate, uploaded to your self-hosted Qualor server. Source: github.com/qualor-dev/qualor
Updated -
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
Go package for implementing shared vulnerability structs for secure analyzers
Updated -
Static security scanner and linter for GitLab CI. Finds .gitlab-ci.yml misconfigurations, supply-chain risks, and leaked secrets. Offline, SARIF output, OWASP CICD-SEC and CWE mappings.
Updated -
Rule Repository for GitLab SAST
Updated -
SAST Analyzer for detecting leaked secrets
Updated -
Static Application Security Testing (SAST) checks your source code for known vulnerabilities.
Updated -
SAST Analyzer for Phoenix Elixir projects based on sobelow
Updated -
SAST Analyzer based on SpotBugs and Find Sec Bugs.
Updated -
Go package for implementing shared vulnerability command interface for secure analyzers
Updated -
SAST Analyzer for Salesforce Apex projects based on pmd
Updated -
Go package for implementing customized rulesets for SAST analyzers
Updated -
GitLab Analyzer for Infrastructure as Code (IaC) projects that calls kics. This analyzer is written in Go using the command library shared by all analyzers.
Updated -
GitLab PipeIntel - Scan GitLab CI pipelines for security and correctness issues using OPA policies and ShellCheck
Updated -
SAST Analyzer for Kubernetes manifests based on kubesec
Updated -
Codequality jobs in pipelines https://docs.gitlab.com/ee/user/project/merge_requests/code_quality.html
Updated