| 10/06 | 9 |
Powerful tool for discovering, classifying, validating, and analyzing leaked credentials.
|
| 10/07 | 8 |
Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities.
|
| 10/07 | 8 |
Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support.
|
| 09/29 | 8 |
Detects passwords, API keys, and tokens in git repos, files, or stdin using configurable, high-performance scanning.
|
| 10/11 | 7 |
Tool that blocks malicious packages during installation by wrapping existing package managers.
|
| 10/10 | 7 |
A GitHub repository CI/CD analyzer that scans for security and best-practice gaps and suggests relevant tools across multiple CI providers and output formats.
|
| 10/09 | 7 |
Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports.
|
| 09/22 | 7 |
Kubernetes security assessment CLI that builds multi-hop RBAC privilege-escalation graphs from live clusters or snapshots and outputs risk-prioritized reports with remediation paths.
|
| 09/20 | 7 |
Multi-ecosystem CLI that scans lockfiles for compromised dependency versions using OSV plus a curated, signed campaign feed with recent-release cooling-off checks and reliable exit codes.
|
| 10/08 | 6 |
High-performance secrets scanner for source code, git history, and binary files, offering CLI, Go library, Burp and Chrome extensions, 459 detection rules, and live credential validation.
|
| 09/21 | 6 |
Static application testing tool that uses semantic-aware pattern matching to find insecure code patterns in Node.js applications.
|
| 09/11 | 6 |
Comprehensive SBOM lifecycle toolkit for assembling, editing, enriching, removing sensitive data, signing, and viewing SBOMs.
|
| 10/07 | 5 |
Zero-code Kubernetes sidecar that redacts PII from logs pre-egress using entropy analysis and deterministic hashing.
|
| 09/30 | 5 |
Cynative is a deep cybersecurity research agent that answers infrastructure questions by running verified, read-only sandboxed code across your cloud, code, and runtime.
|