oxsecurity / codetotal
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security, vulnerability, insecure infrastructure as code, and potential legal issues with open source licenses.
☆76Updated 8 months ago
Alternatives and similar repositories for codetotal:
Users that are interested in codetotal are comparing it to the libraries listed below
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆40Updated this week
- A project to visualize the software supply chain☆50Updated last year
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and vers…☆114Updated last week
- Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks☆58Updated 2 years ago
- FastCVE - fast, rich and API-based search for CVE and more (CPE, CWE, CAPEC)☆49Updated 3 weeks ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 4 months ago
- Dependency Combobulator☆93Updated last year
- ☆110Updated last year
- Manager of third-party sources of Semgrep rules 🗂☆81Updated 9 months ago
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain☆92Updated 2 months ago
- Discover vulnerabilities and container image misconfiguration in production environments.☆55Updated 2 months ago
- 🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends☆72Updated last year
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆133Updated last month
- Binary builds for dep-scan - The Dependency Scanner☆10Updated last year
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆117Updated last year
- Focused malicious code detection ruleset, with a high protection-to-noise ratio☆116Updated 2 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆64Updated 10 months ago
- Kubernetes Pwnage for all☆57Updated 4 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Updated 3 years ago
- My collection of Semgrep rules for vulnerability detection on source code (swift, java)☆34Updated last year
- Efficient DevSecOps☆47Updated 5 months ago
- Virtual environment for learning DevSecOps☆33Updated 7 years ago
- ☆35Updated 9 months ago
- 🔍A cutting edge context aware GraphQL API fuzzing tool!☆140Updated 2 weeks ago
- Konstellation is a configuration-driven CLI tool to enumerate cloud resources and store the data into Neo4j.☆21Updated last year
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git☆91Updated last week
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆22Updated 3 years ago
- Semgrep-based Policy Controller for Kubernetes☆47Updated last month
- ☆189Updated 6 months ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆104Updated 3 months ago