owenrumney / go-sarifLinks
Go library for SARIF - Static Analysis Results Interchange Format
ā81Updated 2 months ago
Alternatives and similar repositories for go-sarif
Users that are interested in go-sarif are comparing it to the libraries listed below
Sorting:
- š° Static taint analysis for Go programs.ā80Updated last month
- Creates CycloneDX Software Bill of Materials (SBOM) from Go modulesā169Updated last month
- Dependency Parser for Multiple Programming Languagesā148Updated last year
- Go implementation of the package url specā67Updated last month
- ā197Updated 3 years ago
- A Server Side Request Forgery (SSRF) protection library. Made with š¤ by Doyensec LLC.ā111Updated 7 months ago
- ā108Updated last year
- Reliable project licenses detector.ā139Updated 4 months ago
- Go library to consume and produce CycloneDX Software Bill of Materials (SBOM)ā100Updated 2 months ago
- Collection of Go packages to work with SPDX filesā156Updated last week
- A lightweight CLI tool that finds system calls being called inside golang applications.ā31Updated 4 years ago
- Go rules for semgrep and go-ruleguardā480Updated last year
- Go module to generate and transform VEX documentsā52Updated 3 weeks ago
- Static Analysis Library for Containersā197Updated 2 years ago
- A Go implementation of in-toto. in-toto is a framework to protect software supply chain integrity.ā142Updated this week
- Common Vulnerability Scoring System (CVSS)ā25Updated last year
- go library for processing container images and simulating a squash filesystemā101Updated last week
- ā58Updated 3 years ago
- ā71Updated last month
- Security scanning & static analysis toolā93Updated last year
- A tool for printing X509 TLS certificates in Goā75Updated last year
- Creates CycloneDX Software Bill-of-Materials (SBOM) from Go projects. So you can use it with DependencyTrack to monitor security issues iā¦ā21Updated 5 years ago
- [mirror] the database client and tools for the Go vulnerability databaseā441Updated 3 weeks ago
- CLI to integrate continuous fuzzing with Fuzzit (no longer available)ā222Updated 5 years ago
- Static code analysis tool to find unsafe usages in Go packages and their dependenciesā44Updated 5 years ago
- Automatic fuzz targets generation for Golang packagesā55Updated last month
- vexctl is a tool to attest VEX impact statementsā45Updated 2 years ago
- fzgo is a prototype of "make fuzzing a first class citizen" in the go command. Supports rich signatures & generating fuzz functions.ā115Updated 4 years ago
- Trivy's misconfiguration scanning engineā215Updated 11 months ago
- [mirror] The Go Vulnerability Databaseā594Updated this week