| 08/13 | 9 |
Powerful tool for discovering, classifying, validating, and analyzing leaked credentials.
|
| 08/27 | 8 |
Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support.
|
| 08/24 | 8 |
Powerful tool for discovering, classifying, validating, and analyzing leaked credentials.
|
| 08/11 | 8 |
Static application testing tool that uses semantic-aware pattern matching to find insecure code patterns in Node.js applications.
|
| 08/26 | 7 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/26 | 7 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 08/25 | 7 |
A GitHub repository CI/CD analyzer that scans for security and best-practice gaps and suggests relevant tools across multiple CI providers and output formats.
|
| 08/25 | 7 |
Tool that blocks malicious packages during installation by wrapping existing package managers.
|
| 08/24 | 7 |
Static application security testing tool that analyzes source code and data flows to find, filter, and prioritize security and privacy risks.
|
| 08/23 | 7 |
A GitHub repository CI/CD analyzer that scans for security and best-practice gaps and suggests relevant tools across multiple CI providers and output formats.
|
| 08/23 | 7 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 08/18 | 7 |
Zero-code Kubernetes sidecar that redacts PII from logs pre-egress using entropy analysis and deterministic hashing.
|
| 08/15 | 7 |
Tool that blocks malicious packages during installation by wrapping existing package managers.
|
| 08/14 | 7 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/07 | 7 |
Detects compromised npm packages and suspicious activities related to the Shai-Hulud 2.0 supply chain attack.
|
| 08/05 | 7 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 07/31 | 7 |
Kubernetes security assessment CLI that builds multi-hop RBAC privilege-escalation graphs from live clusters or snapshots and outputs risk-prioritized reports with remediation paths.
|
| 07/30 | 7 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 07/29 | 7 |
Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support.
|
| 08/27 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/26 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/25 | 6 |
High-performance secrets scanner for source code, git history, and binary files, offering CLI, Go library, Burp and Chrome extensions, 459 detection rules, and live credential validation.
|
| 08/25 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/21 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/18 | 6 |
Detects passwords, API keys, and tokens in git repos, files, or stdin using configurable, high-performance scanning.
|
| 08/13 | 6 |
Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support.
|
| 08/11 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/10 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/09 | 6 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 08/07 | 6 |
Comprehensive SBOM lifecycle toolkit for assembling, editing, enriching, removing sensitive data, signing, and viewing SBOMs.
|
| 08/07 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/07 | 6 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 08/06 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/06 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/04 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 08/02 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 07/31 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 07/30 | 6 |
Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support.
|
| 07/30 | 6 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 07/29 | 6 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 08/24 | 5 |
A GitHub repository CI/CD analyzer that scans for security and best-practice gaps and suggests relevant tools across multiple CI providers and output formats.
|
| 08/22 | 5 |
A GitHub repository CI/CD analyzer that scans for security and best-practice gaps and suggests relevant tools across multiple CI providers and output formats.
|