Projects with this topic
-
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Updated -
Static Application Security Testing (SAST) checks your source code for known vulnerabilities.
Updated -
The uConsole Repo Scan Reporter is a small local workflow for scanning Git repositories with Semgrep and Gitleaks, sending the scanner evidence to a custom Fabric pattern, and optionally publishing the resulting security triage report to Atlassian Confluence. The goal is to provide a lightweight, repeatable workflow for application security engineers, security-minded developers, and field testers who want a local-first way to produce useful security review notes from open source or internal repositories.
Updated -
SAST Analyzer based on SpotBugs and Find Sec Bugs.
Updated -
Codequality jobs in pipelines https://docs.gitlab.com/ee/user/project/merge_requests/code_quality.html
Updated -
AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.
Updated -
Collection of shell scripts packaged with SAST analyzers to enable post-analyzer integrations.
Updated -
This project serves as a comprehensive reference implementation for enterprise DevSecOps practices, demonstrating how security, automation, and observability integrate seamlessly in modern cloud applications.
Updated -
AI-powered security scanner that finds vulnerabilities and provides one-click fixes directly in GitLab merge requests. A reusable CI/CD Catalog component built with Google Cloud Vertex AI.
Updated -
-
Shiftleft CLI auto builder for Docker Hub
Updated -
This repository is part of a master thesis featured on https://scrap.tantemalkah.at and highlights the evaluation of currently maintained F/LOSS static analysis tools for PHP.
Updated