High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
-
Updated
Sep 26, 2026 - Go
High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.
Hands-off supply-chain watchdog for dev machines: orchestrates multiple security scanners (Perplexity bumblebee + osv-scanner, govulncheck, NVIDIA SkillSpector) into one daily verdict — via Claude/Slack, desktop notification, or plain CLI.
Agentic AI for DevSecOps: Transforming Security with GitHub Advanced Security and GitHub Copilot. GitHub Advanced Security - DevSecOps Guidelines - Unified visibility into DevOps security posture. DevSecOps E2E Demos.
Github Action for security scanning utilizing Salus by Coinbase
Stop supply chain attacks before they reach your machine or CI pipeline.
This repo contains the technology stack and its usage for software supply chain security of a Java application
How to secure your development pipeline with static application security test (SAST) / Dynamic application security test (DAST), software composition analysis (SCA) using Sonarqube.
Sheriff is a tool to scan repositories and generate security reports.
AI provenance across your dependency tree. 14 ecosystems. CycloneDX and SPDX integration. Private registry.
Automated security auditing CLI for AI agent code — quarantine-first workflow for repos, packages, and agent tooling
Detect supply chain attacks in Python dependencies. Catches .pth injection, encoding obfuscation, typosquatting, and compromised packages. Zero dependencies, runs in 2 seconds.
Self-hosted, open-source SCA portal — vulnerability (CVE), license compliance, and SBOM management in one UI. Apache-2.0.
CalVigil is an open-source security CLI for scanning dependencies, source code, IaC, containers, binaries, licenses, and supply-chain risks with CI-friendly reports.
Offline, machine-wide Python supply-chain security audit - scan every virtual environment for vulnerable & malicious packages. CVE + typosquat detection, agent/CI-ready JSON. Also a lightweight venv manager.
Open-source local dependency and vulnerability scanner for Java (Maven/Gradle) and JavaScript (npm) projects.
Free dependency vulnerability scanner — scans full transitive tree for CVEs. Supports npm, PyPI, Maven. No signup.
OSS SCA scanner — SBOM + CVE + EUVD + KEV enrichment. Run ottersight scan . locally or in CI.
🛡 Scan GitHub repositories for dependency vulnerabilities using OSV database. Supports npm, PyPI, RubyGems, Go, and PHP.
To associate your repository with the dependency-scanning topic, visit your repo's landing page and select "manage topics."