Privado-Inc / privado-core
The heart & core of Privado code scanner
☆28Updated 2 months ago
Alternatives and similar repositories for privado-core:
Users that are interested in privado-core are comparing it to the libraries listed below
- The Cloud Property Graph is based on a Code Property Graph and tries to connect static code analysis and Cloud runtime assessment.☆22Updated 3 weeks ago
- ShiftLeft OverflowDB☆118Updated 7 months ago
- Interface to initiate code scan with Privado to identify data flows and privacy issues☆15Updated 10 months ago
- Code Property Graph: specification, query language, and utilities☆486Updated last week
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆75Updated 3 weeks ago
- Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various gr…☆73Updated 4 months ago
- Home page of project "KB"☆117Updated 2 months ago
- Codyze is a static analyzer for Java, C, C++ based on code property graphs☆88Updated 3 weeks ago
- A library to extract Code Property Graphs from C/C++, Java, Go, Python, Ruby and every other language through LLVM-IR.☆301Updated this week
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated 11 months ago
- ☆14Updated 2 weeks ago
- A fork of Bandit tool with patterns to identifying malicious python code.☆24Updated 2 years ago
- COVA - A static analysis tool to compute path conditions☆32Updated 2 years ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- SARIF Microsoft Visual Studio Code extension☆113Updated 3 months ago
- CodeQL Security Queries☆24Updated this week
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and vers…☆104Updated last month
- CodeQL queries developed by Trail of Bits☆85Updated last month
- Testability Pattern Catalogs for SAST☆29Updated 11 months ago
- ☆43Updated 7 months ago
- Atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆62Updated 3 weeks ago
- Externalize Java application access to protected resources as log messages.☆41Updated 8 months ago
- Java Observability Toolkit☆61Updated 8 months ago
- Collection of tools for analyzing open source packages.☆329Updated last month
- JoanAudit - A security slicing tool that helps security auditors to perform their security auditing tasks more efficiently☆10Updated 7 years ago
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages☆127Updated 2 years ago
- Code Hierarchy Exploration Net (chen)☆16Updated 3 weeks ago
- A compilation of resources in the software supply chain security domain, with emphasis on open source☆306Updated last year
- Joana - Information Flow Control for Java☆91Updated 3 years ago
- ☆18Updated 6 months ago