ligurio / semgrep-rules
semgrep rules for flakiness, missed error handling, Lua antipatterns and pitfalls.
☆13Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for semgrep-rules
- Custom semgrep rules registry☆12Updated 2 years ago
- My custom semgrep rules☆18Updated 4 years ago
- Low-effort reachability analysis for third-party code vulnerabilities.☆19Updated last year
- Go library for sarif - Static Analysis Results Interchange Format☆66Updated 3 months ago
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆71Updated 3 weeks ago
- Old coverage-guided fuzz testing for fxamacker/cbor. A newer version is used by fxamacker/cbor for fuzzing.☆11Updated last year
- Scan pypi for typosquatting☆37Updated last year
- Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues i…☆21Updated 4 years ago
- ☆22Updated 2 years ago
- Automatic fuzz targets generation for Golang packages☆53Updated 4 months ago
- 🚰 Static taint analysis for Go programs.☆57Updated 3 months ago
- Parallel Delta Debugging Framework☆47Updated this week
- Static code analysis tool to find unsafe usages in Go packages and their dependencies☆41Updated 4 years ago
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- lightweight CVE search☆21Updated last year
- CodeQL queries developed by Trail of Bits☆76Updated this week
- ☆15Updated 4 years ago
- Coverage based JVM Fuzz testing tool.☆19Updated 5 years ago
- egrets monitors egress☆45Updated 4 years ago
- Artifacts of the USENIX Security 2022 paper "Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope"☆17Updated 2 years ago
- Semgrep extension for Visual Studio Code☆54Updated this week
- OSS-Fuzz vulnerabilities for OSV.☆133Updated this week
- ☆24Updated last month
- This novel black-box web vulnerability scanner attempts to infer the state machine of the web application.☆19Updated 4 years ago
- A Security Scanner for Go☆26Updated 5 years ago
- Feed parsing for language package manager updates☆71Updated last week
- Monitoring for leaks of sensitive information in git repositories☆43Updated 11 months ago
- ☆13Updated last month
- Find binary files not installed through package manager☆11Updated last year