semgrep / semgrep-docs
Documentation of Semgrep: a fast, open-source, static analysis tool.
☆40Updated this week
Alternatives and similar repositories for semgrep-docs:
Users that are interested in semgrep-docs are comparing it to the libraries listed below
- ☆23Updated 3 years ago
- Maturity Model Collaborative project☆14Updated 2 years ago
- Dependency Combobulator☆93Updated last year
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆18Updated 4 years ago
- Fork of https://github.com/PortSwigger/param-miner for header smuggling research☆12Updated 3 years ago
- GitHub action to run Threagile, the agile threat modeling toolkit, on a repo's threagile.yaml file☆13Updated 10 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 3 months ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated last year
- ZAP Management Scripts☆23Updated this week
- A tool to run nmap against each line in a script.☆17Updated 4 years ago
- Manager of third-party sources of Semgrep rules 🗂☆81Updated 8 months ago
- ☆58Updated last year
- ☆34Updated 4 years ago
- DefectDojo Community Content☆17Updated 5 months ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆14Updated 3 years ago
- Tools for auditing WAFS☆19Updated 3 years ago
- Kubernetes Security Testing Guide☆26Updated 11 months ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆73Updated 11 months ago
- Reconnaissance test in Kubernetes clusters☆21Updated 6 years ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- A collection of my Semgrep rules☆48Updated last year
- ☆110Updated last year
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 2 weeks ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆27Updated last month
- GCP Audit checks projects in Google Cloud for compliance with CIS Benchmarks☆21Updated 3 weeks ago
- Fast, simple library in Go to fetch CVEs from the National Vulnerability Database feeds☆25Updated last year
- Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool☆25Updated 3 years ago
- Next Generation Phishing Tool For Internal / Red Teams☆35Updated 5 years ago
- Security tools report parsers for Faradaysec.com☆53Updated last week
- An nmap script to produce target lists for use with various tools.☆33Updated 3 years ago