ligurio / semgrep-rules
semgrep rules for flakiness, missed error handling, Lua antipatterns and pitfalls.
โ13Updated 2 months ago
Alternatives and similar repositories for semgrep-rules:
Users that are interested in semgrep-rules are comparing it to the libraries listed below
- Custom semgrep rules registryโ11Updated 2 years ago
- ๐ฐ Static taint analysis for Go programs.โ59Updated 5 months ago
- Go library for sarif - Static Analysis Results Interchange Formatโ70Updated last week
- โ27Updated 8 years ago
- Docker Secure Computing Profile Generatorโ47Updated 3 years ago
- Low-effort reachability analysis for third-party code vulnerabilities.โ20Updated last year
- Automatic fuzz targets generation for Golang packagesโ53Updated 3 weeks ago
- Scan pypi for typosquattingโ38Updated 2 years ago
- Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues iโฆโ21Updated 4 years ago
- egrets monitors egressโ46Updated 4 years ago
- โ29Updated 3 years ago
- Static code analysis tool to find unsafe usages in Go packages and their dependenciesโ42Updated 4 years ago
- A place to systematically store software bill of materials (SBOM) documents.โ44Updated last year
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ38Updated last month
- Detect patterns of bad behavior in function callsโ25Updated 4 years ago
- CodeQL queries developed by Trail of Bitsโ85Updated last month
- Vulnerability Scanner for Detecting Publicly Disclosed Vulnerabilities in Application Dependenciesโ23Updated 5 years ago
- โ15Updated 4 years ago
- Build custom Docker seccomp profiles for containers by finding syscalls it uses.โ89Updated 4 years ago
- Feed parsing for language package manager updatesโ76Updated last month
- A tool for interacting with live processes/containersโ22Updated 2 years ago
- โ22Updated 3 years ago
- Fuzz test Python modules with libFuzzerโ24Updated 2 years ago
- Bad packages from the pypi repositoryโ9Updated 6 years ago
- Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various grโฆโ74Updated 3 months ago
- My custom semgrep rulesโ20Updated 4 years ago
- A Security Scanner for Goโ26Updated 5 years ago
- ShiftLeft Scan is a free and open-source commercial-grade security tool for modern DevOps teams.โ13Updated 2 years ago
- Artifacts of the USENIX Security 2022 paper "Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope"โ17Updated last month
- Go static analysis tool that checks for security issues using an AST.โ28Updated 6 years ago