Skyscanner / sonar-secrets
SonarQube plugin for identifying hardcoded secrets, such as passwords, API keys, AWS credentials, etc..
☆100Updated 11 months ago
Related projects ⓘ
Alternatives and complementary repositories for sonar-secrets
- Integrates OWASP Zed Attack Proxy reports into SonarQube☆69Updated last year
- Container Security Verification Standard☆57Updated 5 years ago
- Software Component Verification Standard (SCVS)☆134Updated 6 months ago
- Github action to run dependency check☆71Updated 3 months ago
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆147Updated 4 years ago
- Node application to help managing Maturity Models like the ones created by BSIMM and OpenSAMM☆187Updated 6 years ago
- Python API library for DefectDojo☆40Updated last year
- Checkmarx Scan and Result Orchestration☆88Updated this week
- Security scanning & static analysis tool☆93Updated 3 weeks ago
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulne…☆31Updated last year
- OWASP Cloud Security - Enabling conversations through threat and control stories☆177Updated 5 years ago
- Discover vulnerabilities and container image misconfiguration in production environments.☆53Updated 2 months ago
- Exports vulnerability scan data from the Checkmarx SAST platform for use in analytical tools.☆20Updated this week
- Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayHub project…☆107Updated 7 months ago
- OWASP Kubernetes Security Testing Guide☆37Updated 2 months ago
- ☆36Updated 3 years ago
- Pin designs for security related items☆37Updated 6 months ago
- OWASP Foundation Web Respository☆27Updated 2 months ago
- OWASP Dependency Track API client for intergration into CI/CD pipeline☆51Updated 3 months ago
- OWASP SonarQube Project☆110Updated 5 years ago
- The OWASP ZAP Jenkins Plugin extends the functionality of the ZAP security tool into a CI Environment.☆58Updated last month
- AppSecPipeline Specification for DevOps automation.☆38Updated last year
- threatspec - continuous threat modeling, through code☆332Updated 3 years ago
- The Secure Coding Framework☆260Updated 4 years ago
- Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.☆46Updated 7 years ago
- A curated list of Software Component Analysis (SCA) books, courses - free and paid, videos, tools, and tutorials.☆98Updated 5 months ago
- OWASP Foundation Web Respository☆54Updated last year
- ☆20Updated 6 years ago
- ☆108Updated last year