owenrumney / go-sarif
Go library for sarif - Static Analysis Results Interchange Format
☆70Updated last week
Alternatives and similar repositories for go-sarif:
Users that are interested in go-sarif are comparing it to the libraries listed below
- 🚰 Static taint analysis for Go programs.☆59Updated 5 months ago
- Creates CycloneDX Software Bill of Materials (SBOM) from Go modules☆140Updated this week
- Go implementation of the package url spec☆56Updated last month
- A Server Side Request Forgery (SSRF) protection library. Made with 🖤 by Doyensec LLC.☆97Updated 8 months ago
- ☆99Updated 5 months ago
- A lightweight CLI tool that finds system calls being called inside golang applications.☆31Updated 3 years ago
- Dependency Parser for Multiple Programming Languages☆146Updated 7 months ago
- Common Vulnerability Scoring System (CVSS)☆24Updated 10 months ago
- Automatic fuzz targets generation for Golang packages☆53Updated 3 weeks ago
- ☆194Updated 2 years ago
- ☆56Updated 2 years ago
- Static analysis for CloudFormation templates to identify common misconfiguration☆57Updated 2 years ago
- Auto-gen Go fuzzing wrappers from normal code. Finds buggy call sequences, including data races & deadlocks. Supports rich signature type…☆106Updated 6 months ago
- Static code analysis tool to find unsafe usages in Go packages and their dependencies☆42Updated 4 years ago
- Go library to consume and produce CycloneDX Software Bill of Materials (SBOM)☆81Updated last week
- Intentionally vulnerable Go web app.☆43Updated last week
- Reliable project licenses detector.☆131Updated 8 months ago
- Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues i…☆21Updated 4 years ago
- ☆52Updated this week
- ☆25Updated 8 months ago
- fatbom (Fat Bill Of Materials) is a tool which combines the SBOM generated by various tools into one fat SBOM. Thus leveraging each tool'…☆32Updated 2 years ago
- Go binary license checker. Extracts module usage information from binaries and analyses their licenses.☆70Updated last year
- Go Taint CHeck Analyser☆44Updated 5 years ago
- ☆65Updated this week
- VCS repository URL parsing library for Go☆31Updated last year
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.☆135Updated this week
- ✨🔐 CNCF Fuzzers☆116Updated 2 weeks ago
- Go beyond package manager discovery for SBOM☆19Updated 2 years ago
- Proposed filepath.SecureJoin implementation☆96Updated this week