semgrep / semgrep-docs
Documentation of Semgrep: a fast, open-source, static analysis tool.
☆40Updated this week
Alternatives and similar repositories for semgrep-docs:
Users that are interested in semgrep-docs are comparing it to the libraries listed below
- Maturity Model Collaborative project☆15Updated 2 years ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- Dependency Combobulator☆93Updated last year
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆23Updated 9 months ago
- A tool to run nmap against each line in a script.☆17Updated 4 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆14Updated 3 years ago
- Manager of third-party sources of Semgrep rules 🗂☆81Updated 9 months ago
- ☆23Updated 3 years ago
- A collection of my Semgrep rules☆49Updated last year
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆76Updated 3 years ago
- ☆10Updated 2 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated last month
- Kubernetes Security Testing Guide☆26Updated last year
- ZAP Management Scripts☆23Updated 3 weeks ago
- ☆57Updated last year
- Collection of Semgrep rules for security analysis☆10Updated last year
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆19Updated 4 years ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated 2 years ago
- AWS Security Checks☆39Updated 7 years ago
- multiple password 'asher using Python’s hashlib☆14Updated 4 years ago
- Static Token And Credential Scanner☆96Updated last year
- Jekyll Files for cloudsecwiki.com☆50Updated 3 years ago
- A Burp plugin to export findings to DefectDojo☆30Updated last year
- Scripts for Sourcegraph search results. Useful for static analysis <3☆27Updated last year
- Konstellation is a configuration-driven CLI tool to enumerate cloud resources and store the data into Neo4j.☆21Updated last year
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆28Updated 2 months ago
- A wrapper around jq, to help you parse jq output!☆30Updated 4 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆47Updated last year
- Anti-Takeover is a sub domain monitoring tool for (blue/purple) team / internal security team which uses cloud flare. Currently Anti-Take…☆12Updated 4 years ago
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆73Updated last year