Yelp / fuzz-lightyear
A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos engineering testing and stateful, Swagger fuzzing.
☆216Updated 8 months ago
Alternatives and similar repositories for fuzz-lightyear:
Users that are interested in fuzz-lightyear are comparing it to the libraries listed below
- Fuzz test your application using your OpenAPI or Swagger API definition without coding☆435Updated 3 weeks ago
- Generic SAST Library☆126Updated 2 months ago
- OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.☆110Updated 2 years ago
- The DevSecOps toolset for REST APIs☆272Updated 2 years ago
- REST API Fuzz Testing (RAFT): Source code for self-hosted service developed for Azure, including the API, orchestration engine, and defau…☆263Updated 3 years ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated 10 months ago
- Security Crawl Maze is a comprehensive testbed for web security crawlers. It contains pages representing many ways in which one can link …☆159Updated 11 months ago
- Predict Mongo ObjectIds☆127Updated 6 years ago
- A starter secure code review checklist☆179Updated 6 years ago
- API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities☆388Updated 7 years ago
- ☆172Updated 3 years ago
- Finding potential software vulnerabilities from git commit messages☆405Updated last year
- threatspec - continuous threat modeling, through code☆340Updated 4 years ago
- ☆176Updated 2 months ago
- Manager of third-party sources of Semgrep rules 🗂☆77Updated 5 months ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- A simple SSRF-testing sheriff written in Go☆322Updated 2 months ago
- A curated list of awesome browser security learning material.☆137Updated 2 years ago
- A Node.js vulnerability finding tool.☆95Updated 4 years ago
- Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki☆202Updated 2 months ago
- Damn Vulnerable Java (EE) Application☆132Updated 11 months ago
- Static security checker for Dockerfiles☆93Updated 9 months ago
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).☆123Updated last year
- Security scanning & static analysis tool☆93Updated 3 months ago
- Code Pulse is a real-time code coverage tool for penetration testing activities☆118Updated 2 years ago
- A community collection of security reviews of open source software components.☆92Updated 10 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆37Updated last month
- Small Python library that makes it easy to exploit race conditions in web apps with Requests.☆158Updated last year
- A cross-platform browser fuzzing framework☆305Updated last month
- Print out URL schemas from an Android app☆117Updated 4 months ago