trivy by aquasecurity

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

created at April 11, 2019, 1:01 a.m.

Go

170 +1

21,796 +75

2,145 +4

GitHub
gitleaks by gitleaks

Protect and discover secrets using Gitleaks 🔑

created at Jan. 27, 2018, 6:19 p.m.

Go

154 +1

15,536 +86

1,335 +7

GitHub
sops by getsops

Simple and flexible tool for managing secrets

created at Aug. 13, 2015, 10:11 p.m.

Go

117 +1

15,402 +38

833 +6

GitHub
trufflehog by trufflesecurity

Find and verify secrets

created at Dec. 31, 2016, 5:08 a.m.

Go

167 +0

14,195 +67

1,544 +9

GitHub
zaproxy by zaproxy

The ZAP core project

created at June 3, 2015, 4:55 p.m.

Java

395 +0

12,164 +38

2,200 +1

GitHub
git-secrets by awslabs

Prevents you from committing secrets and credentials into git repositories

created at July 15, 2015, 8:41 p.m.

Shell

195 +0

12,098 +16

1,157 +0

GitHub
clair by quay

Vulnerability Static Analysis for Containers

created at Nov. 13, 2015, 6:46 p.m.

Go

227 -1

10,101 +5

1,151 -3

GitHub
hadolint by hadolint

Dockerfile linter, validate inline bash, written in Haskell

created at Nov. 15, 2015, 8:20 p.m.

Haskell

68 +0

9,970 +26

403 +1

GitHub
juice-shop by juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

created at Sept. 19, 2014, 2:53 p.m.

TypeScript

157 +1

9,696 +19

9,622 +55

GitHub
docker-bench-security by docker

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

created at May 11, 2015, 12:57 a.m.

Shell

238 +0

8,961 +10

998 +1

GitHub
gosec by GoASTScanner

Go security checker

created at July 18, 2016, 6:01 p.m.

Go

89 +0

7,546 +11

590 +1

GitHub
brakeman by presidentbeef

A static analysis security vulnerability scanner for Ruby on Rails applications

created at Aug. 27, 2010, midnight

Ruby

165 +0

6,925 +3

717 +2

GitHub
checkov by bridgecrewio

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

created at Nov. 27, 2019, 8:55 a.m.

Python

59 +1

6,645 +28

1,062 +4

GitHub
blackbox by StackExchange

Safely store secrets in Git/Mercurial/Subversion

created at April 6, 2014, 5:53 p.m.

Go

121 +0

6,640 +2

370 +0

GitHub
tfsec by aquasecurity

Security scanner for your Terraform code

created at March 4, 2019, 4:56 p.m.

Go

71 +0

6,601 +5

530 -1

GitHub
bandit by PyCQA

Bandit is a tool designed to find common security issues in Python code.

created at April 26, 2018, 9:08 a.m.

Python

66 +0

6,080 +10

585 +1

GitHub
gopass by gopasspw

The slightly more awesome standard unix password manager for teams

created at Feb. 2, 2017, 12:33 p.m.

Go

79 +0

5,700 +9

478 +2

GitHub
phan by phan

Phan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.

created at Oct. 22, 2015, 2:34 p.m.

PHP

108 +0

5,509 +3

360 +0

GitHub
ThreatMapper by deepfence

Open Source Cloud Native Application Protection Platform (CNAPP)

created at Feb. 6, 2020, 10:30 a.m.

TypeScript

58 +0

4,670 +1

572 +0

GitHub
terrascan by tenable

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

created at Sept. 11, 2017, 3:11 a.m.

Go

68 +0

4,563 +15

493 +0

GitHub