patched-codes / semgrep-rulesLinks
A collection of permissively licensed Semgrep rules.
β15Updated last year
Alternatives and similar repositories for semgrep-rules
Users that are interested in semgrep-rules are comparing it to the libraries listed below
Sorting:
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β41Updated 9 months ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratioβ127Updated 7 months ago
- Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of hβ¦β49Updated 7 months ago
- A powerful tool that leverages AI to automatically generate comprehensive security documentation for your projectsβ92Updated last month
- Data about all known supply-chain attacks through historyβ60Updated 4 months ago
- A comprehensive security scanner for Model Context Protocol (MCP) servers that detects vulnerabilities and security issues in your MCP seβ¦β99Updated 3 weeks ago
- SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context Pβ¦β133Updated 4 months ago
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.β73Updated last week
- Unauthenticated enumeration of AWS IAM Roles.β25Updated last month
- β88Updated 8 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. β¦β66Updated 3 months ago
- Manager of third-party sources of Semgrep rules πβ88Updated last year
- Security tool against dependency typosquatting attacksβ54Updated last week
- Semgrep-based Policy Controller for Kubernetesβ47Updated 6 months ago
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs andβ¦β153Updated 10 months ago
- Secure Code Review AI Agent (SeCoRA) - AI SASTβ51Updated 8 months ago
- An OpenAI API Compatible Honeypot Gatewayβ16Updated 6 months ago
- β73Updated 3 weeks ago
- Fork Threat Modeling Platform - Communityβ26Updated 5 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.β23Updated 4 years ago
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or artβ¦β52Updated last week
- β113Updated 2 years ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and versβ¦β129Updated last month
- Pentester-focused Docker registry tool to enumerate and pull imagesβ33Updated 2 months ago
- A small tool to help developers understand a huge set of security requirements from appsec teamsβ47Updated 3 years ago
- Build a CVE library with aggregated CISA, EPSS and CVSS dataβ29Updated 2 years ago
- A very simple open source implementation of Google's Project Naptimeβ169Updated 6 months ago
- A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity programβ43Updated 2 weeks ago
- Demonstrates how a malicious dependency could negatively impact the build output.β24Updated 2 years ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.β35Updated last month