samm by OWASP

SAMM stands for Software Assurance Maturity Model.

created at Aug. 16, 2013, 9:35 a.m.

JavaScript

65 +0

395 +0

132 +0

GitHub
bandit by PyCQA

Bandit is a tool designed to find common security issues in Python code.

created at April 26, 2018, 9:08 a.m.

Python

67 +0

6,057 +15

582 +1

GitHub
hadolint by hadolint

Dockerfile linter, validate inline bash, written in Haskell

created at Nov. 15, 2015, 8:20 p.m.

Haskell

67 +2

9,905 +96

400 +6

GitHub
terrascan by tenable

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

created at Sept. 11, 2017, 3:11 a.m.

Go

68 +1

4,538 +4

495 +1

GitHub
credstash by fugue

A little utility for managing credentials in the cloud

created at April 20, 2015, 4:20 p.m.

Python

70 +0

2,056 +1

217 +0

GitHub
tfsec by aquasecurity

Security scanner for your Terraform code

created at March 4, 2019, 4:56 p.m.

Go

71 +0

6,589 +6

530 +0

GitHub
spotbugs by spotbugs

SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.

created at Nov. 4, 2016, 10:18 p.m.

Java

77 +0

3,371 +7

576 +0

GitHub
gauntlt by gauntlt

a ruggedization framework that embodies the principle "be mean to your code"

created at March 27, 2012, 7:29 p.m.

Ruby

77 +0

972 +0

190 +0

GitHub
NodeGoat by OWASP

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

created at Oct. 21, 2013, 7:14 p.m.

HTML

78 +0

1,834 +3

1,582 +2

GitHub
gopass by gopasspw

The slightly more awesome standard unix password manager for teams

created at Feb. 2, 2017, 12:33 p.m.

Go

79 +0

5,681 +6

475 +0

GitHub
gosec by GoASTScanner

Go security checker

created at July 18, 2016, 6:01 p.m.

Go

89 +0

7,525 +26

589 +1

GitHub
ssllabs-scan by ssllabs

A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing.

created at Oct. 14, 2014, 10:10 a.m.

Go

95 +0

1,683 +1

239 +0

GitHub
phan by phan

Phan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.

created at Oct. 22, 2015, 2:34 p.m.

PHP

107 +0

5,503 +1

360 +0

GitHub
sops by getsops

Simple and flexible tool for managing secrets

created at Aug. 13, 2015, 10:11 p.m.

Go

117 +0

15,302 +44

821 +3

GitHub
blackbox by StackExchange

Safely store secrets in Git/Mercurial/Subversion

created at April 6, 2014, 5:53 p.m.

Go

121 +0

6,636 +6

370 +0

GitHub
gitleaks by gitleaks

Protect and discover secrets using Gitleaks 🔑

created at Jan. 27, 2018, 6:19 p.m.

Go

153 +1

15,400 +27

1,326 +1

GitHub
juice-shop by juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

created at Sept. 19, 2014, 2:53 p.m.

TypeScript

156 +0

9,651 +20

9,526 +49

GitHub
brakeman by presidentbeef

A static analysis security vulnerability scanner for Ruby on Rails applications

created at Aug. 27, 2010, midnight

Ruby

165 +0

6,920 +6

715 +2

GitHub
trufflehog by trufflesecurity

Find and verify secrets

created at Dec. 31, 2016, 5:08 a.m.

Go

167 +1

14,096 +66

1,532 +4

GitHub
trivy by aquasecurity

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

created at April 11, 2019, 1:01 a.m.

Go

169 +0

21,656 +72

2,135 +7

GitHub