shivasurya / code-pathfinder
Code Pathfinder, the open-source alternative to GitHub CodeQL built with GoLang. Built for advanced structural search, derive insights, find vulnerabilities in code.
โ58Updated this week
Alternatives and similar repositories for code-pathfinder:
Users that are interested in code-pathfinder are comparing it to the libraries listed below
- Trail of Bits Testing Handbookโ72Updated last week
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ39Updated 4 months ago
- CodeQL queries developed by Trail of Bitsโ93Updated last week
- Function callpath mapping analysis tool for Goโ33Updated last month
- Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.โ74Updated last year
- Automated vulnerability discovery and annotationโ66Updated 8 months ago
- PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.โ50Updated 2 months ago
- Secure Code Review AI Agent (SeCoRA) - AI SASTโ47Updated 2 months ago
- A security-first linter for code that shouldn't need lintingโ16Updated last year
- Atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.โ64Updated 2 weeks ago
- An experimental AntiBot, AntiCrawl reverse proxy for serving simple static content.โ52Updated 6 months ago
- โ61Updated last week
- A MCP server for using Semgrep to scan code for security vulnerabilities.โ83Updated last week
- Manager of third-party sources of Semgrep rules ๐โ81Updated 8 months ago
- Open Source eBPF Malware Analysis Frameworkโ47Updated 5 months ago
- Repository containing source code of MixewayFlow service that is Swiss army knife for DevSecOps Teamsโ48Updated this week
- Detecting Inconsistencies in Feature or Function Evaluations of Requirementsโ67Updated last year
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.โ36Updated last year
- An IAM Simulator that outputs detailed explains of how a request was evaluated.โ74Updated this week
- Semgrep-based Policy Controller for Kubernetesโ47Updated last week
- eBPF Memory Dump Toolโ64Updated last month
- Identify hardcoded secrets in static structured text (version 2)โ91Updated 2 months ago
- A Completely Modular LLM Reverse Engineering, Red Teaming, and Vulnerability Research Framework.โ46Updated 5 months ago
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetesโ64Updated last week
- โ64Updated 4 months ago
- โ70Updated 2 months ago
- a web fuzzer using the httpipe formatโ100Updated last year
- Static code analyser for backdoors and malicious code in git repos using OpenAI compatible LLM APIsโ72Updated last year
- Unauthenticated enumeration of AWS IAM Roles.โ23Updated 3 months ago
- gradient-based symbolic execution engine implemented from scratchโ35Updated last year