Projects with this topic
-
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
SAST Analyzer for Salesforce Apex projects based on pmd
Updated -
SAST Analyzer based on SpotBugs and Find Sec Bugs.
Updated -
SAST Analyzer based on Semgrep
Updated -
Codequality jobs in pipelines https://docs.gitlab.com/ee/user/project/merge_requests/code_quality.html
Updated -
GitLab PipeIntel - Scan GitLab CI pipelines for security and correctness issues using OPA policies and ShellCheck
Updated -
Anura is an open-source harness platform built by the security research community to create an independent, realistic benchmark for AI systems used in security research. It runs models and agents against real public, authorized bug bounty scopes and security artifacts, then measures what they actually discover, validate, and reject in practical investigations.
Updated -
Early access (beta). REACHABLE AI SAST/SCA with reachability and exploitability proof. Proposes reviewable fix MRs; you merge.
Updated -
Rule Repository for GitLab SAST
Updated -
SAST Analyzer for Kubernetes manifests based on kubesec
Updated -
GitLab's semgrep container image augmented with hundreds of additional Node.js/JavaScript/Typescript and Go rules from Semgrep's rule repository.
Updated -
SAST Analyzer for detecting leaked secrets
Updated -
SAST Analyzer for Phoenix Elixir projects based on sobelow
Updated -
GitLab Analyzer for Infrastructure as Code (IaC) projects that calls kics. This analyzer is written in Go using the command library shared by all analyzers.
Updated -
Veracode Pipeline Scan Component This Veracode Pipeline Scan component runs the Veracode pipeline-scan as an action on any GitHub pipeline
The only pre-requisites is to have the application compiled/packaged according the Veracode Packaging Instructions here
About The pipeline-scan component is designed to be used in a CI/CD pipeline to submit a binary or source code zip to Veracode for security scanning.
For more information on Pipeline Scan, visit the Veracode Docs.
Updated -
Veracode upload and scan component. This component will run a Veracode static scan as Sandbox scan or as policy scan.
Updated -
Veracode SAST Packaging Component This component will run the Veracode CLI package command to prepare the repository for static code analysis. Generated artifacts will be stored behind the name veracode-artifacts.
Updated -
Test project with: Language: Java - Package Manager: Maven
Updated -
Test project with: Language: Python - Package Manager: Pip
Updated -
Test project with: Language: Php - Package Manager: Composer
Updated