Showing 34 of 70 projects
A static code analyzer that detects security vulnerabilities in C# and VB.NET applications.
Static code analyzer for C# and VB.NET that detects bugs, vulnerabilities, and code smells to improve code quality and security.
A lightweight static analysis tool that validates security and correctness characteristics of Windows PE and Linux ELF binaries.
A PostgreSQL extension that performs static analysis and linting for PL/pgSQL stored procedures.
A tool for evaluating the quality of web code generated by Large Language Models (LLMs) using configurable checks and automated repair.
A PHP_CodeSniffer ruleset that detects security vulnerabilities and weaknesses in PHP code, including Drupal 7.
A security tool that scans code for secrets and passwords in JSON, JavaScript, and YAML files via CLI or GitHub PR webhooks.
A collection of GitHub Actions for Snyk to check projects for vulnerabilities across multiple languages and tools.
A deprecated GitHub Action for scanning code with SonarQube Cloud to detect quality and security issues.
A kubectl plugin for security risk analysis of Kubernetes resources like pods, deployments, daemonsets, and statefulsets.
Visualize package dependencies as XKCD-style tower diagrams for Python, Rust, JavaScript, Ruby, PHP, Java, and Go.
A service that shows at a glance if your Rust dependencies are out of date or insecure.
A collection of GitHub Actions and workflows for automating WordPress plugin development, deployment, and quality checks.
Open-source static analysis tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and AI-generated regressions.
Discover internet-wide misconfigurations in services like Elasticsearch, databases, and web servers using high-speed scanning tools.
An automated static analysis engine for PHP that performs automated code reviews and identifies issues.
A security scanning CLI tool that detects vulnerabilities, secrets, and outdated dependencies across multiple programming languages.
A linter for Firefox WebExtensions that validates add-ons for security, performance, and policy compliance.
A community wiki curating static analysis tools (linters) for improving code quality across programming languages and formats.
Open source Terraform module registry with UI, Git integration, security alerts, and cost estimation.
A tool to scan projects for regexes vulnerable to catastrophic backtracking (REDOS) through static extraction, detection, and validation.
A fast TUI for searching, inspecting, and managing Arch Linux and AUR packages with integrated security scans and news.
A containerized tool that codifies unmanaged cloud resources as Terraform, detects drift, estimates costs, and scans for security issues via pull requests.
A self-hosted private Terraform registry for modules and providers with built-in security scanning and documentation.
An open-source tool that combines tflint, tfsec, infracost, and inframap to validate Terraform Infrastructure-as-Code.
A GitHub Action to upload and scan files for malware using VirusTotal's analysis engine.
A database of Magento 1 and 2 extensions with known security vulnerabilities, enabling automated detection of insecure third-party modules.
An open-source container update monitoring tool with a modern dashboard, supporting 23 registries, 20 notification triggers, and automated updates.
A Python tool that scans codebases for potentially dangerous patterns like hardcoded passwords or accidental diff checkins.
A self-hosted Docker management platform with a unified web UI for containers, security, DNS, VPN, monitoring, backups, and multi-node orchestration.
A command-line tool for analyzing server access logs with filters and detailed reports.
A collection of pre-commit hooks for automating formatting, validation, security scanning, and documentation of OpenTofu configurations.
A Docker container that simplifies and secures Infrastructure as Code deployments by running security scans before IaC tools.
A GitHub Action that runs tfsec with reviewdog on pull requests to enforce Terraform security best practices.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.