Showing 36 of 227 projects
Static vulnerability analysis for container images (OCI/Docker) via an API that indexes and matches against known security flaws.
An open-source platform for continuous code quality inspection and security analysis across 30+ programming languages.
Automated PHP code upgrades and refactoring tool that instantly updates PHP versions and major frameworks.
Standard libraries and queries for CodeQL, powering GitHub Advanced Security and static application security testing.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and reverse engineering.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and penetration testing.
A comprehensive ESLint plugin providing React-specific linting rules to enforce best practices and catch common errors.
Automated code review tool that integrates with any linter and posts results as comments on pull requests.
A community-driven static code analysis tool that detects errors and potential problems in JavaScript code.
A development tool that helps programmers write Java code adhering to configurable coding standards and best practices.
A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.
A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.
A static analysis tool that scans Go source code for security vulnerabilities by analyzing the AST and SSA representations.
A Go library and toolset for parsing, formatting, and interpreting POSIX Shell, Bash, and Zsh scripts.
A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.
A static code analysis tool that scans infrastructure as code, container images, and open source packages for security misconfigurations and vulnerabilities.
A static analysis tool for detecting security misconfigurations and flaws in Nginx configuration files.
A retargetable machine-code decompiler based on LLVM, supporting multiple architectures and file formats.
A very fast and accurate code counter with complexity calculations, COCOMO/LOCOMO estimates, and unique line metrics written in pure Go.
An opinionated, zero-config ESLint wrapper for JavaScript/TypeScript with great defaults and automatic fixes.
An opinionated, zero-config ESLint wrapper for JavaScript and TypeScript with great defaults and automatic fixes.
A TypeScript validator that maintains 1:1 type-safety from editor to runtime with optimized performance.
A standalone binary inspection tool for Android developers to browse executables and analyze bytecode.
A static analysis security vulnerability scanner for Ruby on Rails applications.
A static analysis tool for Java that catches common programming mistakes at compile-time.
A performant, incremental type checker for Python with integrated security analysis via Pysa.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static analysis security scanner for Terraform code that identifies misconfigurations across major cloud providers.
A static code analysis tool for Kotlin that identifies code smells and enforces coding standards.
A state-of-the-art static analysis linter for Go that finds bugs, performance issues, and enforces style rules.
A state-of-the-art static analysis linter for Go that finds bugs, performance issues, and enforces style rules.
A safe, zero-overhead FFI bridge for calling C++ code from Rust and Rust code from C++.
A static analysis tool for detecting bugs and undefined behavior in C and C++ code.
Visualize call graphs of Go programs using interactive Graphviz-based diagrams.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.