pyt
semgrep-rules
Our great sponsors
pyt | semgrep-rules | |
---|---|---|
2 | 8 | |
2,161 | 704 | |
0.3% | 2.6% | |
0.0 | 9.5 | |
over 3 years ago | 3 days ago | |
Python | Solidity | |
GNU General Public License v3.0 only | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
pyt
- python-security/pyt - A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications
-
Security Audit of 3rd Party Packages
https://github.com/python-security/pyt (no longer maintained, but still works).
semgrep-rules
-
Powerful SAST project for Android Application Security
Nice and all, but why not contribute to https://github.com/returntocorp/semgrep-rules ?
-
Semgrep - Beta support for Rust
Well, the rules they actually added are pretty noisy. There's also not a lot of them.
-
Spring Actuator - Finding Actuators using Static Code Analysis - Part 2
The semgrep registry contains lots of rules for many issues, and you can contribute your own.
-
Just Say No To `:Latest`
Hadolint is great! If you want to customize your lint logic beyond the checks in it, I recently wrote a Semgrep rule to require all our Dockerfiles to pin images with a sha256 hash that could be a good starting point: https://github.com/returntocorp/semgrep-rules/pull/1861/file...
-
RCE 0-day exploit found in log4j, a popular Java logging package
Semgrep Rules for searching source code
-
Hacktoberfest and open-source security
Interested? More details are in this Hacktoberfest README.
- Semgrep rules registry: 1300 linter rules
What are some alternatives?
bap - Binary Analysis Platform
find-sec-bugs - The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
klara - Automatic test case generation for python and static analysis library
CVE-2021-44228-Log4Shell-Hashes - Hashes for vulnerable LOG4J versions
aura - Python source code auditing and static analysis on a large scale
ZAP - The ZAP core project
pycg - Static Python call graph generator
pyre-check - Performant type-checking for python.
fxpmath - A python library for fractional fixed-point (base 2) arithmetic and binary manipulation with Numpy compatibility.
Log4JShell-Bytecode-Detector - Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)
manticore - Symbolic execution tool
hadolint - Dockerfile linter, validate inline bash, written in Haskell