SonarQubeCommunity / sonar-fortifyLinks
Fortify SCA Plugin for SonarQube
☆14Updated 4 years ago
Alternatives and similar repositories for sonar-fortify
Users that are interested in sonar-fortify are comparing it to the libraries listed below
Sorting:
- Fortify SonarQube Plugin☆22Updated 4 years ago
- python restful api fuzz test☆50Updated 2 years ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 3 years ago
- Generic SAST Library☆133Updated 6 months ago
- A tiny Java agent that blocks attacks against unsafe deserialization☆86Updated 8 years ago
- Java taint propagation for java. Define tainted sources, sanitizer methods and sinks via aspects.☆29Updated 7 years ago
- A technique for developing Fortify structural rules and characterization rules.☆14Updated 6 years ago
- A collection of various scripts and automations to simplify Checkmarx SAST and IAST setup and use☆14Updated 7 years ago
- Yet Another Source Code Analyzer☆184Updated 3 years ago
- Evaluation Framework for Dependency Analysis (EFDA)☆44Updated 3 years ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆124Updated 7 years ago
- Binary rewriting approach with fork server support to fuzz Java applications with afl-fuzz.☆90Updated 7 years ago
- Web Input Vector Extractor Teaser☆132Updated 3 years ago
- Automate security tests using Burp Suite.☆232Updated last year
- Read and write Fortify Project (FPR) files in Python☆41Updated 6 years ago
- Vulnerable Java based Web Application☆271Updated last year
- Java Deserialization☆27Updated 9 years ago
- Custom Fortify SCA rules to detect common JSSE certification validation flaws☆11Updated 10 years ago
- poc or exp of some famous vulnerability☆14Updated 11 years ago
- collection of ppt/pdf from security conferences☆19Updated 2 years ago
- MOSEC-X-PLUGIN 后端API服务☆24Updated 5 years ago
- Trigger automated Acunetix scans as part of your web application's build process☆32Updated last year
- Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.☆146Updated 8 years ago
- Repository to showcase various configuration recipes with various technologies☆37Updated 3 years ago
- Baseline IoT security checklist. Consider security as early in development as possible and reap the rewards.☆30Updated 8 years ago
- Code Pulse is a real-time code coverage tool for penetration testing activities☆122Updated 3 years ago
- HTML5 WebSocket message fuzzer☆148Updated 7 years ago
- The Web Application Vulnerability Scanner Evaluation Project☆238Updated 3 years ago
- Repository to hold materials for DefCon_RESTing presentation by Dinis, Abe and Alvaro☆53Updated 12 years ago
- Java web and command line applications demonstrating various security topics☆237Updated last week