semgrep / semgrepLinks
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
☆14,074Updated this week
Alternatives and similar repositories for semgrep
Users that are interested in semgrep are comparing it to the libraries listed below
Sorting:
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆31,602Updated this week
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆8,331Updated this week
- Simple and flexible tool for managing secrets☆20,671Updated last week
- A vulnerability scanner for container images and filesystems☆11,469Updated this week
- An HTTP toolkit for security research.☆9,278Updated last year
- Vulnerability Static Analysis for Containers☆10,924Updated this week
- CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security☆9,216Updated this week
- 🐶 Automated code review tool integrated with any code analysis tools regardless of programming language☆9,056Updated this week
- Vulnerability scanner written in Go which uses the data provided by https://osv.dev☆8,416Updated this week
- Make JSON greppable!☆14,363Updated 8 months ago
- jq for binary formats - tool, language and decoders for working with binary and text formats☆10,410Updated this week
- a structural diff that understands syntax 🟥🟩☆24,062Updated last week
- An enterprise friendly way of detecting and preventing secrets in code.☆4,412Updated 10 months ago
- Super simple build framework with fast, repeatable builds and an instantly familiar syntax – like Dockerfile and Makefile had a baby.☆11,973Updated 3 months ago
- Go security checker☆8,651Updated this week
- A code rewrite tool for structural search and replace that supports ~every language.☆2,599Updated 5 months ago
- Open source vulnerability DB and triage service.☆2,475Updated this week
- Find secrets with Gitleaks 🔑☆24,786Updated last month
- Dolt – Git for Data☆19,684Updated last week
- OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependen…☆7,423Updated this week
- Snyk CLI scans and monitors your projects for security vulnerabilities.☆5,407Updated this week
- Hurl, run and test HTTP requests with plain text.☆18,472Updated this week
- RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security…☆2,867Updated 3 weeks ago
- ⚡A CLI tool for code structural search, lint and rewriting. Written in Rust☆12,363Updated this week
- Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.☆1,072Updated this week
- A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.☆21,179Updated last week
- Pulumi - Infrastructure as Code in any programming language 🚀☆24,638Updated this week
- ⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The foc…☆14,367Updated 2 weeks ago
- OpenSSF Scorecard - Security health metrics for Open Source☆5,262Updated this week
- An operating system designed for hosting containers☆9,527Updated last week