oxsecurity / codetotalLinks
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
β78Updated last year
Alternatives and similar repositories for codetotal
Users that are interested in codetotal are comparing it to the libraries listed below
Sorting:
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.β56Updated 4 months ago
- Manager of third-party sources of Semgrep rules πβ88Updated last year
- β113Updated 2 years ago
- Dependency Combobulatorβ93Updated last year
- Secrets scanner that understands codeβ188Updated last year
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chainβ95Updated 8 months ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsβ105Updated 8 months ago
- Virtual environment for learning DevSecOpsβ37Updated 7 years ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and versβ¦β129Updated last month
- truffleproc β hunt secrets in process memory (TruffleHog & gdb mashup)β119Updated 2 years ago
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β41Updated 9 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.β23Updated 4 years ago
- An extension to use Semgrep inside Burp Suite.β89Updated 4 months ago
- Nuclei plugins to audit Chrome extensionsβ65Updated last year
- boostsecurityio/lotpβ134Updated 5 months ago
- Blogpost series showcasing interesting cloud - web app security bugsβ49Updated 2 years ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratioβ127Updated 7 months ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.β21Updated 7 months ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raiderβ139Updated 4 years ago
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β137Updated 6 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.β44Updated this week
- A comprehensive list of software composition analysis tools.β156Updated last year
- π Visualize and explore IaC βοΈ Create and share notes in VS Code π€ Sync notes and findings in real-time with friendsβ74Updated last year
- Find CVE PoCs on GitHubβ153Updated 2 months ago
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilitiesβ29Updated 6 months ago
- Prototype of Full Agentic Application Security Testing, FAAST = SAST + DAST + LLM agentsβ63Updated 5 months ago
- WAF bypass PoCβ49Updated 2 years ago
- β60Updated 2 years ago
- β17Updated 3 years ago
- GCP GOAT is the vulnerable application for learn the GCP Securityβ67Updated 4 months ago