Open-source web app scanner.
Tools for devsecops
Shift-left scanning in CI/CD pipelines.
54 tools indexed
Policy-as-code across the stack.
Multi-cloud security posture.
QARK
—Quick Android Review Kit.
Detect vulnerable JS libraries.
Self-hosted open-source WAF.
API fuzzer from OpenAPI/GraphQL.
Lightweight static analysis.
Solidity / Vyper static analyzer.
Open-source SCA + IaC scanner.
Solidity inspector.
Syft
—Generate SBOMs from containers and source code.
Cloud-native secrets manager.
eBPF-based runtime security.
Cross-platform data-protection framework.
Open-source cloud-native protection platform.
Container and IaC vulnerability scanner.
Find leaked credentials at scale.
Google's network vulnerability scanner.
Vuls
—Agent-less Linux vulnerability scanner.
Pre-commit secret detection.
LLM vulnerability scanner.
Golang security checker.
Google's general-purpose fuzzer.