opengrep / opengrep-rules
☆61Updated last month
Alternatives and similar repositories for opengrep-rules:
Users that are interested in opengrep-rules are comparing it to the libraries listed below
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆170Updated 4 months ago
- ☆164Updated 6 months ago
- boostsecurityio/poutine☆259Updated 3 weeks ago
- A tool for preventing the installation of malicious PyPI and npm packages☆129Updated this week
- Protect against subdomain takeover☆93Updated 10 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 3 months ago
- The security workflow engine!☆105Updated this week
- Gram is Klarna's own threat model diagramming tool☆319Updated last week
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆111Updated last month
- ☆98Updated 2 weeks ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆83Updated 2 weeks ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆39Updated last year
- A full insecure kubernetes application for testing security tools☆70Updated last week
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆61Updated 9 months ago
- Enriching the NVD CVSS scores to include Temporal & Threat Metrics☆174Updated this week
- An open-source collection of API key rotation tutorials.☆67Updated last week
- AWS honey token manager☆87Updated 7 months ago
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆132Updated last year
- Cloud Commotion intends to cause chaos to simulate security incidents☆145Updated 9 months ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆148Updated 4 months ago
- A tool to check the security settings of Github Organizations.☆71Updated last year
- ☆175Updated 4 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆138Updated 2 months ago
- Enrich SBOMs with data from third party services☆161Updated last month
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆30Updated 5 months ago
- Use AI to Scan Your Code from the Command Line for security and code smells. Bring your own keys. Supports OpenAI and Gemini☆161Updated last year
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year
- A Risk-Based Prioritization Taxonomy for prioritizing CVEs (Common Vulnerabilities and Exposures).☆72Updated 10 months ago
- boostsecurityio/lotp☆116Updated last week
- ☆43Updated 2 months ago