ligurio / semgrep-rules
semgrep rules for flakiness, missed error handling, Lua antipatterns and pitfalls.
ā13Updated 5 months ago
Alternatives and similar repositories for semgrep-rules:
Users that are interested in semgrep-rules are comparing it to the libraries listed below
- Automatic fuzz targets generation for Golang packagesā53Updated 2 months ago
- š° Static taint analysis for Go programs.ā63Updated 2 weeks ago
- ā15Updated 4 years ago
- Custom semgrep rules registryā11Updated 2 years ago
- ā26Updated last month
- Artifacts of the USENIX Security 2022 paper "Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope"ā17Updated 3 months ago
- Go library for SARIF - Static Analysis Results Interchange Formatā73Updated this week
- ShiftLeft Scan is a free and open-source commercial-grade security tool for modern DevOps teams.ā13Updated 2 years ago
- A place to systematically store software bill of materials (SBOM) documents.ā44Updated last year
- efficient linux security monitoringā26Updated 6 years ago
- OSS-Sydr-Fuzz - OSS-Fuzz fork for hybrid fuzzing (fuzzer+DSE) open source software.ā139Updated last week
- ā29Updated 2 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.ā40Updated this week
- Corpus for github.com/dvyukov/go-fuzz examplesā197Updated 4 years ago
- ā22Updated 3 years ago
- egrets monitors egressā45Updated 4 years ago
- Parallel Delta Debugging Frameworkā52Updated 3 months ago
- [beta] Use Semgrep in LLMs using MCP frameworkā12Updated last week
- CodeQL queries developed by Trail of Bitsā90Updated 3 months ago
- Monitoring for leaks of sensitive information in git repositoriesā43Updated last year
- Detect patterns of bad behavior in function callsā26Updated 4 years ago
- Function callpath mapping analysis tool for Goā33Updated 3 weeks ago
- ā82Updated 6 months ago
- BPF based FIM solutionā42Updated last year
- Detect compiler names and versions from ELF filesā25Updated 6 months ago
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and oā¦ā74Updated last week
- OSS-Fuzz vulnerabilities for OSV.ā149Updated this week
- My custom semgrep rulesā20Updated 4 years ago
- Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues iā¦ā21Updated 5 years ago
- A framework for streamlining the capture of PANDA execution traces.ā56Updated 4 years ago