Awesome Devsecops
Section: Static Analysis · Microsoft - A set of IDE plugins, CLIs and other tools that provide security analysis for a number of programming languages.
Entry
Appears in 5 awesome lists
DevSkim is a set of IDE plugins and rules that provide security "linting" capabilities. Also has support for CLI so it can be integrated into CI/CD pipeline.
Section: Static Analysis · Microsoft - A set of IDE plugins, CLIs and other tools that provide security analysis for a number of programming languages.
Section: 代码分析和指标 · DevSkim是IDE扩展和语言分析器的框架,可在开发人员编写代码时在开发环境中提供内联安全性分析。
Section: Static Code Analysis · DevSkim is a set of IDE plugins and rules that provide security "linting" capabilities. Also has support for CLI so it can be integrated into CI/CD pipeline.
Section: Multiple languages · Regex-based static analysis tool for Visual Studio, VS Code, and Sublime Text - C/C++, C#, PHP, ASP, Python, Ruby, Java, and others.
Section: Code Analysis and Metrics · A set of IDE plugins and rules that provide security "linting" capabilities.
Python Code Quality Authority - Find common security vulnerabilities in Python code.
JS Foundation - Linting tool for JavaScript with multiple security linting rules available.
Open-Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.
SonarQube empowers development teams with a code quality and security solution that deeply integrates into your enterprise environment; enabling you to deploy clean code consistently and reliably. SonarQube provides a free and open source Community Build.
Justin Collins - Static analysis tool which checks Ruby on Rails applications for security vulnerabilities.
Prevents you from committing passwords and other sensitive information to a git repository.
A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.
Diagnostic analyzers developed by the Roslyn team. Initially developed to help flesh out the design and implementation of the static analysis APIs. The analyzers cover code quality, .NET Core, desktop .NET Framework, comments in code, and more.