There are 4 repositories under code-scanning topic.
A GitHub Security Lab initiative, providing an in-repo learning experience, where learners secure intentionally vulnerable code.
Extensions to the PHP Reflection API, static code scanning, and code generation
Actions for running CodeQL analysis
🚀 Useful README.md, LICENSE, CONTRIBUTING.md, CODE_OF_CONDUCT.md, SECURITY.md, GitHub Issues, Pull Requests and Actions templates to jumpstart your projects.
⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle
Telling tales on you for leaking secrets!
🔧 JetBrains Qodana’s official command line tool
codemillx is a tool for CodeQL, extract the comments in the code and generate codeql module. 强化Go开源项目安全检测(内含开源项目漏洞挖掘方法)
NaiveSystems Analyze is a static analysis tool for code security and compliance.
This repository contains CodeQL queries and libraries which support various Coding Standards.
GitHub Advance Security Compliance Action
An open-source security suite aiming to combine structural code analysis with AI-powered vulnerability detection. Built for advanced structural search, derive insights, find vulnerabilities in code.
Code scanner to check for issues in prompts and LLM calls
Codety Scanner is a comprehensive code scanner designed to detect code issues for 30+ programming languages and IaC frameworks. It embeds more than 6,000 code analysis rules and can detect code smells, vulnerable code, secrets in the code, performance issues, style violations, and more.
A GitHub action for organizations that enables advanced security code scanning on all new repos
GitHub Action for filtering Code Scanning alerts by path and id
CodeScanAI is an open source tool that utilizes powerful AI models (OpenAI, Gemini, and even self-hosted servers) to scan your codebase for possible security vulnerabilities.
Action to retrofit a CodeQL bundle with additional queries, libraries, and customizations
GitHub Action to run Bandit
A monorepo filtering workaround for GitHub Advanced Security Code Scanning using renaming of the scanning tool in an Actions workflow
Mirror of kettle @ core.tcl.tk/akupries -- A build system for pure Tcl, and critcl packages
Lets Threat Model is an AI-driven tool that helps teams identify and manage threats early in the development lifecycle. Built with extensibility and automation in mind, it brings security into agile workflows by generating actionable threat models.
A template repository to help you get started with Code Scanning on GitHub
my code
A secret scanner wrapper to aggregate results across multiple secret scanning tools
Adapters and tools for lintrunner
Simple header-only IDA-style code scanner
The OSV-Scanner vulnerability scanner as a snap 📦