🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
-
Updated
Jun 21, 2026 - Rust
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
Detect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. 950+ rules.
Lightweight static analyzer for several programming languages
Harden your package manager configs against supply chain attacks.
Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity.
⚡ Fast Web Security Scanner written in Rust based on Lua Scripts 🌖 🦀
Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++ projects
Open-source secret scanner in Rust. Service-specific detectors, SIMD on the CPU and an optional GPU path, live verification of which leaked keys are still active, and SARIF output.
Rust scanner for ScanCode-compatible workflows, licenses, package metadata, SBOMs, and provenance data.
Git-native AI code provenance: records which AI agent wrote which line, signs each attribution with ed25519, stores it in your git history. Cross-agent (Claude Code, Cursor, Copilot, Codex, Windsurf, OpenCode, Gemini).
🛡️ Blazing fast Supply Chain Security tool written in Rust. Features ephemeral sandboxing, hybrid analysis (CVE + Heuristics), and entropy-based malware detection.
Polyglot execution engine and CLI for vulnerability detection using real code
Vyoma: Run Docker images as high-performance MicroVMs. Powered by Cloud-Hypervisor & Rust, offering hardware-level isolation with sub-1second boot times and a familiar Docker-like CLI
🔐 Secrets, configs, and platform outputs as code — typed, versioned, encrypted.
Qryon — Find security vulnerabilities in seconds. 647+ rules, 28 languages, 10x faster than Semgrep. Free & open source CLI.
Pin your GitHub Actions. Prick holes in their supply chain security.
Paranoid security scanner + sandboxed step runner for GitHub Actions. Verifies pins, audits workflows, runs steps in a kernel sandbox where secrets are capabilities.
UZYNTRA API Firewall is a high-performance API security engine that inspects, detects, and mitigates threats in real time through a programmable reverse proxy architecture.
Add a description, image, and links to the devsecops topic page so that developers can more easily learn about it.
To associate your repository with the devsecops topic, visit your repo's landing page and select "manage topics."