Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure DevOps, Google CloudBuild, VS Code and Visual Studio. No server required!
☆149Sep 4, 2020Updated 5 years ago
Alternatives and similar repositories for sast-scan
Users that are interested in sast-scan are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆879Sep 1, 2023Updated 2 years ago
- ☆17Jun 22, 2026Updated 2 months ago
- 安卓activity劫持演示demo,包含指定activity位于前台时的劫持和指定进程位于前台时的劫持☆15Dec 20, 2018Updated 7 years ago
- Static code auditing system☆467Jan 8, 2021Updated 5 years ago
- ☆15Jul 11, 2018Updated 8 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- GitHub Action adding a comment with information about new npm dependencies detected in a pull request☆18Jun 22, 2026Updated 2 months ago
- Generic server for collaborative code analysis☆13Dec 19, 2016Updated 9 years ago
- njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.☆453Aug 11, 2026Updated 2 weeks ago
- Web Input Vector Extractor Teaser☆131Jan 6, 2022Updated 4 years ago
- This is a collection of ZAProxy Automation Tools and scripts to automate security tests of WEB Applications and WEB Sites☆26May 14, 2023Updated 3 years ago
- Snyk Node Runtime Agent☆16Apr 12, 2022Updated 4 years ago
- ☆245Updated this week
- Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilit…☆552Apr 10, 2022Updated 4 years ago
- ☆107Apr 2, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Linux/Unix config Checking tools☆13Jun 6, 2014Updated 12 years ago
- Codyze is a static analyzer for Java, C, C++ based on code property graphs☆90Aug 4, 2026Updated 3 weeks ago
- Terraform module which provides easy to configure AWS environment for running automated security scanning solutions at scheduled interval…☆47Jan 29, 2019Updated 7 years ago
- Hunter作为中通DevSecOps闭环方案中的一环,扮演着很重要的角色,开源之后希望能帮助到更多企业。☆341Dec 14, 2022Updated 3 years ago
- ☆187Feb 20, 2025Updated last year
- Kubernetes tools in a "distroless" container☆13Oct 30, 2023Updated 2 years ago
- Collection of enterprise application patterns☆18Jun 14, 2026Updated 2 months ago
- ICSE 2018 paper implement☆17Jan 8, 2019Updated 7 years ago
- Docker + CVE-2015-2925 = escaping from --volume☆11Jun 30, 2015Updated 11 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆12Feb 17, 2016Updated 10 years ago
- A framework for interacting with HCL AppScan on Cloud and HCL AppScan Enterprise☆12Mar 3, 2023Updated 3 years ago
- Pin designs for security related items☆37Feb 16, 2026Updated 6 months ago
- Ready to use images of Zap and Glue, especially for CI integration.☆35Mar 12, 2019Updated 7 years ago
- A companion repo to accompany detailed guides and YouTube content to allow users to follow along☆13Aug 29, 2020Updated 6 years ago
- MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool☆35Dec 28, 2025Updated 8 months ago
- ☆10May 12, 2017Updated 9 years ago
- Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various gr…☆78Oct 14, 2024Updated last year
- An AWS Lambda Port Scanner and SSL expiry checker☆12Dec 4, 2016Updated 9 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- nodejsscan is a static security code scanner for Node.js applications.☆2,572Oct 10, 2025Updated 10 months ago
- AWS Serverless Security☆400Jul 13, 2022Updated 4 years ago
- Parser utility to generate ASTs from PHP source code suitable to be processed by Joern.☆37Apr 21, 2020Updated 6 years ago
- A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC☆32Apr 30, 2026Updated 4 months ago
- Making CoreOS' Clair easily work in CI/CD pipelines☆29Sep 10, 2023Updated 2 years ago
- Automatic tool using for crawling code to find low-hang fruit vulnerabilities - Based on OWASP Secure Code Review Guide☆21Aug 31, 2020Updated 6 years ago
- Security Development LifeCycle Process (安全开发生命周期参考)☆27Nov 27, 2018Updated 7 years ago