All Projects → Gosec → Similar Projects or Alternatives

911 Open source projects that are alternatives of or similar to Gosec

Insider
Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C#, and Javascript (Node.js).
Stars: ✭ 216 (-96.21%)
Huskyci
Performing security tests inside your CI
Stars: ✭ 398 (-93.01%)
Fwanalyzer
a tool to analyze filesystem images for security
Stars: ✭ 382 (-93.29%)
codeclimate-duplication
Code Climate engine for code duplication analysis
Stars: ✭ 96 (-98.31%)
Krane
Kubernetes RBAC static Analysis & visualisation tool
Stars: ✭ 254 (-95.54%)
Mutual labels:  static-analysis, security-tools
duplex
Duplicate code finder for Elixir
Stars: ✭ 20 (-99.65%)
phpstan-webmozart-assert
PHPStan extension for webmozart/assert
Stars: ✭ 132 (-97.68%)
codeclimate-eslint
Code Climate Engine for ESLint
Stars: ✭ 86 (-98.49%)
static-code-analysis-plugin
A plugin to simplify Static Code Analysis on Gradle. Not restricted to, but specially useful, in Android projects, by making sure all analysis can access the SDK classes.
Stars: ✭ 36 (-99.37%)
Reviewdog
🐶 Automated code review tool integrated with any code analysis tools regardless of programming language
Stars: ✭ 4,541 (-20.25%)
Pmd
An extensible multilanguage static code analyzer.
Stars: ✭ 3,667 (-35.6%)
Prealloc
prealloc is a Go static analysis tool to find slice declarations that could potentially be preallocated.
Stars: ✭ 419 (-92.64%)
Phpstan Phpunit
PHPUnit extensions and rules for PHPStan
Stars: ✭ 247 (-95.66%)
tryceratops
A linter to prevent exception handling antipatterns in Python (limited only for those who like dinosaurs).
Stars: ✭ 381 (-93.31%)
sonarlint4netbeans
SonarLint integration for Apache Netbeans
Stars: ✭ 23 (-99.6%)
lints
Lint all your JavaScript, CSS, HTML, Markdown and Dockerfiles with a single command
Stars: ✭ 14 (-99.75%)
analysis-model
A library to read static analysis reports into a Java object model
Stars: ✭ 74 (-98.7%)
OpenStaticAnalyzer
OpenStaticAnalyzer is a source code analyzer tool, which can perform deep static analysis of the source code of complex systems.
Stars: ✭ 19 (-99.67%)
unimport
A linter, formatter for finding and removing unused import statements.
Stars: ✭ 119 (-97.91%)
gotcha
Go Taint CHeck Analyser
Stars: ✭ 40 (-99.3%)
Wsltools
Web Scan Lazy Tools - Python Package
Stars: ✭ 288 (-94.94%)
Phpstan Strict Rules
Extra strict and opinionated rules for PHPStan
Stars: ✭ 295 (-94.82%)
Awesome Dotnet Security
Awesome .NET Security Resources
Stars: ✭ 325 (-94.29%)
Mutual labels:  static-analysis, security-tools
Pytype
A static type analyzer for Python code
Stars: ✭ 3,545 (-37.74%)
Wssat
WEB SERVICE SECURITY ASSESSMENT TOOL
Stars: ✭ 360 (-93.68%)
Mutual labels:  static-analysis, security-tools
Super
Secure, Unified, Powerful and Extensible Rust Android Analyzer
Stars: ✭ 340 (-94.03%)
Wala
T.J. Watson Libraries for Analysis
Stars: ✭ 395 (-93.06%)
Warnings Ng Plugin
Jenkins Warnings Plugin - Next Generation
Stars: ✭ 248 (-95.64%)
Dg
[LLVM Static Slicer] Various program analyses, construction of dependence graphs and program slicing of LLVM bitcode.
Stars: ✭ 242 (-95.75%)
Engine
Droidefense: Advance Android Malware Analysis Framework
Stars: ✭ 386 (-93.22%)
Revive
🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
Stars: ✭ 3,139 (-44.87%)
phpstan-nette
Nette Framework class reflection extension for PHPStan & framework-specific rules
Stars: ✭ 87 (-98.47%)
klara
Automatic test case generation for python and static analysis library
Stars: ✭ 250 (-95.61%)
unimport
unimport is a Go static analysis tool to find unnecessary import aliases.
Stars: ✭ 64 (-98.88%)
Larastan
⚗️ Adds code analysis to Laravel improving developer productivity and code quality.
Stars: ✭ 3,554 (-37.58%)
eba
EBA is a static bug finder for C.
Stars: ✭ 14 (-99.75%)
nakedret
nakedret is a Go static analysis tool to find naked returns in functions greater than a specified function length.
Stars: ✭ 82 (-98.56%)
codeclimate-phpcodesniffer
Code Climate Engine for PHP Code Sniffer
Stars: ✭ 27 (-99.53%)
identypo
identypo is a Go static analysis tool to find typos in identifiers (functions, function calls, variables, constants, type declarations, packages, labels).
Stars: ✭ 26 (-99.54%)
qodana-action
⚙️ Scan your Java, Kotlin, PHP, Python, JavaScript, TypeScript projects at GitHub with Qodana
Stars: ✭ 112 (-98.03%)
analysis-net
Static analysis framework for .NET programs.
Stars: ✭ 19 (-99.67%)
Soteria
Plugin to block compilation when unapproved dependencies are used or code styling does not comply.
Stars: ✭ 36 (-99.37%)
Sonar Php
🐘 SonarPHP: PHP static analyzer for SonarQube & SonarLint
Stars: ✭ 288 (-94.94%)
Securecodebox
secureCodeBox (SCB) - continuous secure delivery out of the box
Stars: ✭ 279 (-95.1%)
Bandit
Bandit is a tool designed to find common security issues in Python code.
Stars: ✭ 3,763 (-33.91%)
Nullaway
A tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead
Stars: ✭ 3,035 (-46.7%)
W5
Security Orchestration, Automation and Response (SOAR) Platform. 安全编排与自动化响应平台,无需编写代码的安全自动化,使用 SOAR 可以让团队工作更加高效
Stars: ✭ 367 (-93.55%)
Pylint
It's not just a linter that annoys you!
Stars: ✭ 3,733 (-34.44%)
Patrowlmanager
PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
Stars: ✭ 363 (-93.62%)
Chronos
Chronos - A static race detector for the go language
Stars: ✭ 272 (-95.22%)
Phpstan Symfony
Symfony extension for PHPStan
Stars: ✭ 360 (-93.68%)
Shodansploit
🔎 shodansploit > v1.3.0
Stars: ✭ 342 (-93.99%)
Taipan
Web application vulnerability scanner
Stars: ✭ 359 (-93.7%)
Phpstan Doctrine
Doctrine extensions for PHPStan
Stars: ✭ 338 (-94.06%)
Awesome Java Security
Awesome Java Security Resources 🕶☕🔐
Stars: ✭ 216 (-96.21%)
Mutual labels:  static-analysis, security-tools
Forbidden Apis
Policeman's Forbidden API Checker
Stars: ✭ 216 (-96.21%)
Mquery
YARA malware query accelerator (web frontend)
Stars: ✭ 264 (-95.36%)
Semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Stars: ✭ 5,668 (-0.46%)
Burpa
Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application Security Testing (DAST).
Stars: ✭ 427 (-92.5%)
Applicationinspector
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
Stars: ✭ 3,873 (-31.98%)
Mutual labels:  static-analysis, security-tools
1-60 of 911 similar projects