High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
-
Updated
Oct 5, 2026 - Go
High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.
Hands-off supply-chain watchdog for dev machines: orchestrates multiple security scanners (Perplexity bumblebee + osv-scanner, govulncheck, NVIDIA SkillSpector) into one daily verdict — via Claude/Slack, desktop notification, or plain CLI.
Agentic AI for DevSecOps: Transforming Security with GitHub Advanced Security and GitHub Copilot. GitHub Advanced Security - DevSecOps Guidelines - Unified visibility into DevOps security posture. DevSecOps E2E Demos.
A visual builder for AI workflows with security designed in: SSRF-guarded requests, rate limiting and encrypted BYOK keys. Includes an OSV.dev dependency scanner whose AI report can't change its findings. MIT licensed.
Github Action for security scanning utilizing Salus by Coinbase
Stop supply chain attacks before they reach your machine or CI pipeline.
Offline lockfile vulnerability triage with optional OSV output
This repo contains the technology stack and its usage for software supply chain security of a Java application
How to secure your development pipeline with static application security test (SAST) / Dynamic application security test (DAST), software composition analysis (SCA) using Sonarqube.
Sheriff is a tool to scan repositories and generate security reports.
AI provenance across your dependency tree. 14 ecosystems. CycloneDX and SPDX integration. Private registry.
Detect supply chain attacks in Python dependencies. Catches .pth injection, encoding obfuscation, typosquatting, and compromised packages. Zero dependencies, runs in 2 seconds.
Automated security auditing CLI for AI agent code — quarantine-first workflow for repos, packages, and agent tooling
Self-hosted, open-source SCA portal — vulnerability (CVE), license compliance, and SBOM management in one UI. Apache-2.0.
OSS SCA scanner — SBOM + CVE + EUVD + KEV enrichment. Run ottersight scan . locally or in CI.
CalVigil is an open-source security CLI for scanning dependencies, source code, IaC, containers, binaries, licenses, and supply-chain risks with CI-friendly reports.
Offline, machine-wide Python supply-chain security audit - scan every virtual environment for vulnerable & malicious packages. CVE + typosquat detection, agent/CI-ready JSON. Also a lightweight venv manager.
Open-source local dependency and vulnerability scanner for Java (Maven/Gradle) and JavaScript (npm) projects.
To associate your repository with the dependency-scanning topic, visit your repo's landing page and select "manage topics."