patched-codes / semgrep-rulesLinks
A collection of permissively licensed Semgrep rules.
β12Updated 11 months ago
Alternatives and similar repositories for semgrep-rules
Users that are interested in semgrep-rules are comparing it to the libraries listed below
Sorting:
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β39Updated 6 months ago
- Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of hβ¦β36Updated 4 months ago
- Manager of third-party sources of Semgrep rules πβ87Updated 11 months ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratioβ120Updated 4 months ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and versβ¦β120Updated 2 weeks ago
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.β52Updated 3 weeks ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.β23Updated 3 years ago
- β69Updated 2 weeks ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.β41Updated last week
- Collection of Semgrep rules for security analysisβ10Updated last year
- β71Updated 5 months ago
- Security tool against dependency typosquatting attacksβ52Updated this week
- A command line tool for detecting vulnerabilities in Python dependencies and doing safe package installsβ51Updated 2 years ago
- β17Updated last week
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.β68Updated 2 weeks ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. β¦β65Updated this week
- Semgrep-based Policy Controller for Kubernetesβ47Updated 2 months ago
- Maturity Model Collaborative projectβ15Updated 2 years ago
- β36Updated 10 months ago
- DefectDojo Community Contentβ18Updated 3 weeks ago
- β74Updated this week
- Unauthenticated enumeration of AWS IAM Roles.β25Updated 5 months ago
- Code Pathfinder, the open-source alternative to GitHub CodeQL built with GoLang. Built for advanced structural search, derive insights, fβ¦β62Updated 3 weeks ago
- A project to visualize the software supply chainβ51Updated last year
- My collection of Semgrep rules for vulnerability detection on source code (swift, java)β34Updated last year
- Modular web-application honeypot platform built using go and ginβ58Updated last year
- HashiCorp-relevant rules for the Semgrep code analysis toolβ41Updated last year
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.β35Updated 6 months ago
- CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and securitβ¦β53Updated 4 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.β41Updated last year