OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
☆7,719Oct 5, 2026Updated this week
Alternatives and similar repositories for DependencyCheck
Users that are interested in DependencyCheck are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supp…☆4,264Updated this week
- Integrates Dependency-Check reports into SonarQube☆695Updated this week
- The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala proje…☆2,449Mar 26, 2026Updated 6 months ago
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆38,282Updated this week
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆9,080Dec 4, 2025Updated 10 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆3,718Jan 9, 2025Updated last year
- Vulnerability Static Analysis for Containers☆11,068Sep 30, 2026Updated last week
- Open-Source Unified Vulnerability Management, DevSecOps & ASPM☆4,984Updated this week
- The ZAP by Checkmarx Core project☆15,889Updated this week
- Source Code Security Audit (源代码安全审计)☆3,185Sep 16, 2022Updated 4 years ago
- 🔥Open source RASP solution☆2,987Oct 2, 2025Updated last year
- Java web common vulnerabilities and security code which is base on springboot and spring security☆2,672Dec 2, 2024Updated last year
- Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.☆16,901Updated this week
- A simple Java command-line utility to mirror the CVE JSON data from NIST.☆214Nov 4, 2022Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.☆3,949Updated this week
- Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…☆2,682Mar 14, 2024Updated 2 years ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆31,795Updated this week
- Pre-Built Vulnerable Environments Based on Docker-Compose☆21,321Sep 18, 2026Updated 2 weeks ago
- CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security☆10,173Updated this week
- A powerful browser crawler for web vulnerability scanners☆3,041Mar 11, 2025Updated last year
- The cheat sheet about Java Deserialization vulnerabilities☆3,185May 26, 2023Updated 3 years ago
- scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.☆4,180Updated this week
- A vulnerability scanner for container images and filesystems☆12,986Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Find secrets with Gitleaks 🔑☆29,774Sep 30, 2026Updated last week
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,647Updated this week
- 📦 Make security testing of K8s, Docker, and Containerd easier.☆4,765May 1, 2026Updated 5 months ago
- Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and …☆21,897Sep 30, 2026Updated last week
- KunLun-M — Open-source static code analysis for PHP, Nodejs/JavaScript, Python, Golang, Java and C/C++, with AST-based semantic scanning …☆2,416Sep 28, 2026Updated last week
- Find, verify, and analyze leaked credentials☆28,307Updated this week
- Web application fuzzer☆6,590Jan 21, 2026Updated 8 months ago
- Open-source and AI-powered cybersecurity tools for offensive security, vulnerability management, and autonomous pentesting. Built by hack…☆6,771Updated this week
- SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list☆6,144Mar 10, 2021Updated 5 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆842Jun 7, 2022Updated 4 years ago
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,405Dec 16, 2022Updated 3 years ago
- IAST 灰盒扫描工具☆446Jul 19, 2022Updated 4 years ago
- In-depth attack surface mapping and asset discovery☆15,320Jul 19, 2026Updated 2 months ago
- 一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档☆11,754Oct 29, 2024Updated last year
- A byte code analyzer for finding deserialization gadget chains in Java applications☆1,090Jun 15, 2021Updated 5 years ago
- Burp suite 分块传输辅助插件☆2,026Feb 23, 2022Updated 4 years ago