opengrep / opengrep-rules
☆60Updated 2 months ago
Alternatives and similar repositories for opengrep-rules:
Users that are interested in opengrep-rules are comparing it to the libraries listed below
- boostsecurityio/poutine☆263Updated 2 weeks ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆171Updated 4 months ago
- A tool for preventing the installation of malicious PyPI and npm packages☆134Updated this week
- ☆165Updated 7 months ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆114Updated last month
- Enriching the NVD CVSS scores to include Temporal & Threat Metrics☆193Updated this week
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆92Updated last week
- A full insecure kubernetes application for testing security tools☆70Updated 2 weeks ago
- The security workflow engine!☆109Updated this week
- Protect against subdomain takeover☆93Updated 10 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆40Updated last year
- ☆100Updated 2 weeks ago
- 🖇️ STRIDE vs. ASVS equivalence table☆76Updated 7 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆62Updated 9 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 4 months ago
- Gram is Klarna's own threat model diagramming tool☆320Updated last month
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆132Updated last year
- Test & Compare different Kubernetes security offerings on EKS, GKE and AKS☆39Updated 7 months ago
- boostsecurityio/lotp☆121Updated this week
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆148Updated 4 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated last year
- Enrich SBOMs with data from third party services☆165Updated 2 weeks ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆107Updated last year
- ☆112Updated 3 months ago
- ☆176Updated 4 months ago
- Nextdoor's Cloud Security Posture Management (CSPM) Evaluation Matrix☆58Updated last year
- AWS honey token manager☆87Updated 8 months ago
- Scans your Github Actions for security issues☆64Updated last month
- A utility to (re-)import findings and language data into DefectDojo☆43Updated 6 months ago
- A tool to check the security settings of Github Organizations.☆71Updated last year