Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security Scanning

Security Scanning

76 projects

Showing 36 of 76 projects

repomix
repomixTypeScript

Pack your entire codebase into a single AI-friendly file for analysis by LLMs like Claude, ChatGPT, and Gemini.

#ai#developer-tools#openai
Stars27.4k
Forks1.4k
Last commit1 day ago
Static Analysis & Code Quality
Static Analysis & Code QualityRust

A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more.

#hacktoberfest#developer-tools#linter
Stars14.7k
Forks1.5k
Last commit
Awesome Static Analysis
Awesome Static AnalysisRust

A curated directory of static analysis (SAST) tools and linters for all programming languages, config files, and build tools.

#hacktoberfest#developer-tools#linter
Stars14.7k
Forks1.5k
Last commit
Grype
GrypeGo

A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.

#container-security#vulnerability#sbom-analysis
Stars12.6k
Forks836
Last commit1 day ago
Grype
GrypeGo

A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.

#container-security#vulnerability#sbom-analysis
Stars12.6k
Forks836
Last commit1 day ago
sonarqube
sonarqubeJava

An open-source platform for continuous code quality inspection and security analysis across 30+ programming languages.

#devops#software-metrics#security-scanning
Stars10.8k
Forks2.2k
Last commit1 day ago
checkov
checkovPython

A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.

#aws-security#azure#kubernetes
Stars8.9k
Forks1.4k
Last commit12 days ago
Checkov
CheckovPython

A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.

#aws-security#azure#static-code-analysis
Stars8.9k
Forks1.4k
Last commit12 days ago
tfsec
tfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#azure#terraform-security
Stars7.0k
Forks555
Last commit4 months ago
Tfsec
TfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#rego#google-cloud-platform#multi-cloud
Stars7.0k
Forks555
Last commit4 months ago
TFSec
TFSecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#multi-cloud#azure
Stars7.0k
Forks555
Last commit4 months ago
tfsec
tfsecGo

A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.

#google-cloud-platform#multi-cloud#azure
Stars7.0k
Forks555
Last commit4 months ago
Psalm
PsalmPHP

A static analysis tool for finding errors and security vulnerabilities in PHP applications.

#hacktoberfest#developer-tools#taint-analysis
Stars5.9k
Forks700
Last commit11 days ago
scorecard
scorecardGo

Automated security health metrics for open source projects, assessing security best practices and risks.

#supply-chain-security#security-scanning#openssf-scorecard
Stars5.6k
Forks680
Last commit4 days ago
terrascan
terrascanGo

A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.

#devops#terrascan#policy-as-code
Stars5.2k
Forks556
Last commit8 months ago
Terrascan
TerrascanGo

A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.

#devops#terrascan#kubernetes
Stars5.2k
Forks556
Last commit8 months ago
detect-secrets
detect-secretsPython

An enterprise-friendly Python tool for detecting and preventing secrets from entering codebases with a baseline approach.

#enterprise-security#secret-detection#pre-commit-hook
Stars4.6k
Forks562
Last commit3 months ago
Axiom
AxiomShell

A dynamic infrastructure framework for distributing security scanning workloads across multiple cloud instances.

#ffuf#multi-cloud#dnsx
Stars4.4k
Forks718
Last commit1 year ago
ApplicationInspector
ApplicationInspectorC#

A source code analyzer that identifies features and characteristics in software components using static analysis and a JSON rules engine.

#multi-language#dotnet-tool#rules-engine
Stars4.4k
Forks367
Last commit2 days ago
Spotbugs
SpotbugsJava

A static analysis tool for finding bugs in Java code, succeeding the FindBugs project.

#hacktoberfest#linter#static-code-analysis
Stars3.9k
Forks668
Last commit3 days ago
Design Review Workflow
Design Review Workflow

A collection of automated AI-powered workflows for code review, security scanning, and design review using Claude Code agents.

#devops#workflow-automation#claude-code
Stars3.9k
Forks564
Last commit10 months ago
scans
scansJavaScript

An open-source Cloud Security Posture Management (CSPM) tool that scans AWS, Azure, GCP, Oracle, and GitHub for security misconfigurations.

#aws-security#compliance-auditing#infrastructure-security
Stars3.8k
Forks748
Last commit5 months ago
pre-commit-terraform
pre-commit-terraformShell

A collection of pre-commit hooks for automating code quality, security, and documentation checks for Terraform, OpenTofu, and Terragrunt configurations.

#hooks#hacktoberfest#terraform-docs
Stars3.7k
Forks582
Last commit
kube-linter
kube-linterGo

A static analysis tool that checks Kubernetes YAML files and Helm charts for security and production readiness best practices.

#hacktoberfest#helm#devops
Stars3.5k
Forks268
Last commit2 days ago
Teller
TellerRust

A universal secret manager CLI for developers that centralizes secrets from multiple providers and prevents secret sprawl.

#environment-variables#rust-lang#secrets-management
Stars3.2k
Forks201
Last commit5 months ago
Bearer
BearerGo

Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.7k
Forks143
Last commit4 days ago
Bearer
BearerGo

A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.7k
Forks143
Last commit4 days ago
KICS
KICSOpen Policy Agent

KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.

#hacktoberfest#kubernetes#security-scanning
Stars2.7k
Forks377
Last commit2 days ago
Security
SecurityJavaScript

ESLint plugin that identifies potential security vulnerabilities in Node.js code, requiring human triage for false positives.

#developer-tools#security-scanning#vulnerability-detection
Stars2.4k
Forks110
Last commit
The Claude Agent Skill for Terraform and OpenTofu - testing, modules, CI/CD, and production patterns
The Claude Agent Skill for Terraform and OpenTofu - testing, modules, CI/CD, and production patterns

A Claude Agent skill providing best practices, testing strategies, and CI/CD workflows for Terraform and OpenTofu infrastructure code.

#devops#claude-agent#opentofu
Stars2.2k
Forks196
Last commit21 days ago
is-website-vulnerable
is-website-vulnerableJavaScript

Scans websites for publicly known security vulnerabilities in frontend JavaScript libraries using the Snyk database.

#hacktoberfest#snyk-integration#frontend-security
Stars2.0k
Forks128
Last commit
SSL Labs Scan
SSL Labs ScanGo

A command-line client for SSL Labs APIs, enabling automated and bulk SSL/TLS security assessments.

#web-security#ssl-tls#security-scanning
Stars1.8k
Forks249
Last commit1 year ago
Stelligent/cfn_nag
Stelligent/cfn_nagRuby

A linting tool that scans AWS CloudFormation templates for insecure infrastructure patterns and security violations.

#cloudformation-templates#continuous-testing#devops
Stars1.3k
Forks209
Last commit2 years ago
SonarJS
SonarJSTypeScript

A static code analyzer for JavaScript, TypeScript, and CSS that detects quality and security issues.

#sonarcloud#language-team#code-metrics
Stars1.3k
Forks193
Last commit22 hours ago
Cherrybomb
CherrybombRust

A CLI tool that audits API specifications, validates OpenAPI compliance, and runs security tests to prevent undefined user behavior.

#firecracker#business-logic#cyber
Stars1.2k
Forks84
Last commit1 year ago
Awesome Dynamic Analysis
Awesome Dynamic AnalysisMarkdown

A curated list of dynamic analysis tools and linters for all programming languages, binaries, and more.

#software-testing#developer-tools#dynamic-code-analysis
Stars1.1k
Forks118
Last commit
Page 1 of 3

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
1 month ago
1 month ago
22 hours ago
1 day ago
1 day ago
4 days ago
Next
#Static Analysis40
#Devsecops30
#Ci Cd27
#Infrastructure As Code22
#Code Quality21
#Security20
#Devops18
#Terraform18
#Docker17
#Aws13
#Cloud Security12
#Compliance12