semgrep / semgrep-vscodeLinks
Semgrep extension for Visual Studio Code
☆73Updated this week
Alternatives and similar repositories for semgrep-vscode
Users that are interested in semgrep-vscode are comparing it to the libraries listed below
Sorting:
- This project is deprecated. Use https://github.com/returntocorp/semgrep instead☆74Updated last year
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆48Updated this week
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers…☆135Updated last week
- SARIF Microsoft Visual Studio Code extension☆132Updated this week
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆98Updated last month
- CVE database☆21Updated 5 years ago
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆84Updated last week
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆42Updated last year
- Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks☆61Updated 3 years ago
- DefectDojo Community Content☆18Updated 3 months ago
- Prepackaged and precompiled github codeql container for rapid analysis, deployment and development.☆123Updated 2 years ago
- Vulnogram is the tool for reserving, managing, and publishing CVEs. Get started at vulnogram.org or deploy Docker edition for full enterp…☆214Updated 3 weeks ago
- Golang installer for DefectDojo☆29Updated last year
- ☆114Updated 2 years ago
- A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos enginee…☆226Updated last year
- Deptective automatically determines the native dependencies required to run any arbitrary program or command.☆127Updated last month
- A wrapper around jq, to help you parse jq output!☆30Updated 5 years ago
- Trail of Bits Testing Handbook - appsec.guide☆92Updated this week
- A set of Python command line tools for working with SARIF files produced by code analysis tools☆140Updated 5 months ago
- Generate thousands of pull requests to fix widespread security vulnerabilities across GitHub.☆36Updated 8 months ago
- Modular framework for file information extraction and dependency analysis to generate accurate SBOMs☆39Updated this week
- A React-based component for viewing SARIF files.☆103Updated last year
- A tool to automatically detect copy+pasted and vendored code between repositories☆74Updated this week
- Data about all known supply-chain attacks through history☆63Updated 8 months ago
- ☆16Updated 2 years ago
- A security-first linter for code that shouldn't need linting☆17Updated 2 years ago
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆97Updated this week
- A fast port scanner written in go with a focus on reliability and simplicity.☆21Updated last year
- ☆10Updated 3 years ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆68Updated 7 months ago