Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Rust
  3. Cherrybomb

Cherrybomb

Apache-2.0Rustv1.0.1

A CLI tool that audits API specifications, validates OpenAPI compliance, and runs security tests to prevent undefined user behavior.

GitHubGitHub
1.2k stars84 forks0 contributors

What is Cherrybomb?

Cherrybomb is a CLI tool that audits API specifications, validates OpenAPI compliance, and runs security tests to prevent undefined user behavior. It helps developers catch specification errors and vulnerabilities early in the development process, reducing security risks and ensuring APIs function as intended.

Target Audience

API developers, security engineers, and DevOps teams who need to validate OpenAPI specifications and integrate security testing into their CI/CD pipelines.

Value Proposition

Cherrybomb offers a comprehensive, configurable approach to API validation and security testing, with detailed reporting that pinpoints issues for easy remediation. Its Rust-based performance and flexible profiles make it a robust alternative to manual specification reviews.

Overview

Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

Use Cases

Best For

  • Validating OpenAPI specifications for compliance and best practices
  • Running security tests on API endpoints during development
  • Integrating API security scanning into CI/CD pipelines
  • Generating detailed parameter and endpoint tables from OpenAPI files
  • Auditing APIs for common vulnerabilities before production deployment
  • Configuring custom security and testing profiles for specific API needs

Not Ideal For

  • Teams needing immediate, plug-and-play CI/CD integration without setup delays
  • Environments requiring containerized tools without API key dependencies
  • Projects that rely on intrusive or fully customizable security testing profiles
  • Organizations preferring graphical interfaces over CLI tools for API auditing

Pros & Cons

Pros

Robust Spec Validation

Checks OpenAPI specifications for compliance with OAS rules and best practices, ensuring APIs meet industry standards as highlighted in the README.

Flexible Testing Profiles

Offers multiple profiles like info, normal, passive, and full, allowing users to tailor audit depth based on specific testing needs.

Detailed Issue Reporting

Provides precise location information for identified problems, making it easy to fix errors with clear output examples shown in the README.

Configurable via JSON

Supports configuration files for customizing testing parameters, server overrides, and security settings, enhancing adaptability for different API environments.

Cons

Installation Hurdles

Installation methods for Linux/MacOS and containerized versions are deprecated, forcing users to build from source or use cargo, which can be complex and time-consuming.

Incomplete Features

Key features like the intrusive profile and config options for including/excluding checks are marked as 'in development', limiting functionality for advanced use cases.

CI Integration Uncertainty

CI pipeline integration is deprecated and will be replaced, causing instability for teams wanting to embed it immediately into their workflows without future changes.

Frequently Asked Questions

Quick Stats

Stars1,236
Forks84
Contributors0
Open Issues31
Last commit1 year ago
CreatedSince 2021

Tags

#firecracker#business-logic#cyber#api#openapi-validation#security-scanning#cli-tool#security#devsecops#security-tools#api-testing#ci-cd-integration#cli#cybersecurity#rust#api-security

Built With

R
Rust
D
Docker

Included in

Rust56.6k
Auto-fetched 10 hours ago

Related Projects

rustscanrustscan

🤖 The Modern Port Scanner 🤖

Stars20,381
Forks1,380
Last commit1 day ago
feroxbusterferoxbuster

A fast, simple, recursive content discovery tool written in Rust.

Stars8,058
Forks633
Last commit3 days ago
rayhunterrayhunter

Rust tool to detect cell site simulators on an orbic mobile hotspot

Stars5,786
Forks484
Last commit18 hours ago
rustnetrustnet

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Stars5,001
Forks231
Last commit2 days ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub