* [TruffleHog v3.97.1](https://github.com/trufflesecurity/trufflehog) – Powerful tool for discovering, classifying, validating, and analyzing leaked credentials. * [Chainloop v1.107.0](https://github.com/chainloop-dev/chainloop) – Evidence store and policy engine for Software Supply Chain attestations, SBOMs, VEX, SARIF, and QA reports. * [Skylos v4.35.0](https://github.com/duriantaco/skylos) – Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities. * [Zanadir 0.3.0](https://github.com/MustacheCase/zanadir) – A GitHub repository CI/CD analyzer that scans for security and best-practice gaps and suggests relevant tools across multiple CI providers and output formats. * [Package Manager Guard (PMG) v0.27.0](https://github.com/safedep/pmg) – Tool that blocks malicious packages during installation by wrapping existing package managers. * [Bearer v2.1.1](https://github.com/Bearer/bearer) – Static application security testing tool that analyzes source code and data flows to find, filter, and prioritize security and privacy risks. * [Titus v1.2.8](https://github.com/praetorian-inc/titus) – High-performance secrets scanner for source code, git history, and binary files, offering CLI, Go library, Burp and Chrome extensions, 459 detection rules, and live credential validation.