patched-codes / semgrep-rulesLinks
A collection of permissively licensed Semgrep rules.
โ12Updated 11 months ago
Alternatives and similar repositories for semgrep-rules
Users that are interested in semgrep-rules are comparing it to the libraries listed below
Sorting:
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ39Updated 5 months ago
- Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of hโฆโ34Updated 3 months ago
- Manager of third-party sources of Semgrep rules ๐โ86Updated 10 months ago
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.โ52Updated last week
- An OpenAI API Compatible Honeypot Gatewayโ16Updated 2 months ago
- Focused malicious code detection ruleset, with a high protection-to-noise ratioโ120Updated 3 months ago
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.โ66Updated this week
- Build a CVE library with aggregated CISA, EPSS and CVSS dataโ27Updated last year
- Collection of Semgrep rules for security analysisโ10Updated last year
- Semgrep-based Policy Controller for Kubernetesโ47Updated 2 months ago
- Maturity Model Collaborative projectโ15Updated 2 years ago
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.โ35Updated 5 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. โฆโ65Updated 11 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.โ41Updated this week
- A command line tool for detecting vulnerabilities in Python dependencies and doing safe package installsโ51Updated 2 years ago
- Code Pathfinder, the open-source alternative to GitHub CodeQL built with GoLang. Built for advanced structural search, derive insights, fโฆโ60Updated this week
- DefectDojo Community Contentโ18Updated 7 months ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.โ23Updated 3 years ago
- Security tool against dependency typosquatting attacksโ52Updated this week
- Modular web-application honeypot platform built using go and ginโ58Updated last year
- A security-first linter for code that shouldn't need lintingโ16Updated last year
- Unauthenticated enumeration of AWS IAM Roles.โ25Updated 4 months ago
- Fork Threat Modeling Platform - Communityโ20Updated last month
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.โ41Updated last year
- A project to visualize the software supply chainโ52Updated last year
- Tool for obfuscating and deobfuscating data.โ70Updated last year
- Analysis of the Enterprise SAST/DAST product landscapeโ37Updated last year
- โ68Updated 4 months ago
- Automated vulnerability discovery and annotationโ67Updated 10 months ago
- โ72Updated 3 weeks ago