semgrep / semgrep-vscode
Semgrep extension for Visual Studio Code
☆54Updated this week
Alternatives and similar repositories for semgrep-vscode:
Users that are interested in semgrep-vscode are comparing it to the libraries listed below
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆38Updated this week
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆73Updated 9 months ago
- ☆22Updated 3 years ago
- Custom semgrep rules registry☆11Updated 2 years ago
- Feed parsing for language package manager updates☆76Updated last month
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆37Updated last month
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- ☆28Updated 2 years ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆22Updated 6 months ago
- ☆18Updated 11 months ago
- ☆17Updated last year
- DefectDojo Community Content☆17Updated 3 months ago
- SARIF Microsoft Visual Studio Code extension☆113Updated 3 months ago
- My custom semgrep rules☆20Updated 4 years ago
- ☆41Updated this week
- Simple tool to identify and remediate the use of the AWS EC2 IMDSv1.☆16Updated 3 years ago
- ☆13Updated 3 months ago
- semgrep rules for flakiness, missed error handling, Lua antipatterns and pitfalls.☆13Updated 2 months ago
- Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis.☆22Updated last year
- Security scanning & static analysis tool☆93Updated 3 months ago
- Low-effort reachability analysis for third-party code vulnerabilities.☆20Updated last year
- ☆10Updated last year
- A community collection of security reviews of open source software components.☆92Updated 10 months ago
- StartLeft is an automation tool for generating Threat Models written in the Open Threat Model (OTM) format from a variety of different so…☆49Updated this week
- Trail of Bits Testing Handbook☆60Updated this week
- A documentation and tracking project with the goal of making package management systems more secure.☆50Updated 3 years ago
- Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks☆57Updated 2 years ago
- A set of Python command line tools for working with SARIF files produced by code analysis tools☆95Updated last week