opengrep / opengrep-rules
☆63Updated 3 months ago
Alternatives and similar repositories for opengrep-rules:
Users that are interested in opengrep-rules are comparing it to the libraries listed below
- boostsecurityio/poutine☆267Updated last week
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.☆172Updated 5 months ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆95Updated last month
- A tool for preventing the installation of malicious PyPI and npm packages☆141Updated this week
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Updated last year
- A full insecure kubernetes application for testing security tools☆85Updated 2 weeks ago
- OWASP Foundation Web Respository☆82Updated 3 months ago
- ☆180Updated 3 weeks ago
- Enriching the NVD CVSS scores to include Temporal & Threat Metrics☆194Updated this week
- Enrich SBOMs with data from third party services☆171Updated last month
- The security workflow engine!☆111Updated last week
- Cloud Commotion intends to cause chaos to simulate security incidents☆143Updated 10 months ago
- ☆64Updated last week
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,…☆133Updated last year
- Protect against subdomain takeover☆92Updated 11 months ago
- AWS honey token manager☆87Updated 9 months ago
- ☆104Updated last week
- ☆45Updated 4 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated last year
- A powerful tool that leverages AI to automatically generate comprehensive security documentation for your projects☆76Updated 3 weeks ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆116Updated 2 months ago
- A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity program☆15Updated last week
- boostsecurityio/lotp☆123Updated 3 weeks ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.☆108Updated last year
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆148Updated 5 months ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆209Updated 3 weeks ago
- Tooling to simulate runtime attacks and test default runtime detections from Datadog Cloud Security Management.☆31Updated 6 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆64Updated 10 months ago
- Automate vulnerability triage which prioritizes remediation over discovery☆17Updated last week
- A standard API specification for exchanging supply chain artifacts and intelligence☆79Updated this week