Skip to content

Entry

DevSkim

Appears in 5 awesome lists

DevSkim is a set of IDE plugins and rules that provide security "linting" capabilities. Also has support for CLI so it can be integrated into CI/CD pipeline.

Open github.commicrosoft/devskim

Found in these lists

Awesome Devsecops

Section: Static Analysis · Microsoft - A set of IDE plugins, CLIs and other tools that provide security analysis for a number of programming languages.

StaleScore 52

说明

Section: 代码分析和指标 · DevSkim是IDE扩展和语言分析器的框架,可在开发人员编写代码时在开发环境中提供内联安全性分析。

StaleScore 53

Contents

Section: Static Code Analysis · DevSkim is a set of IDE plugins and rules that provide security "linting" capabilities. Also has support for CLI so it can be integrated into CI/CD pipeline.

FreshScore 78

Static Analysis

Section: Multiple languages · Regex-based static analysis tool for Visual Studio, VS Code, and Sublime Text - C/C++, C#, PHP, ASP, Python, Ruby, Java, and others.

FreshScore 91

Awesome .NET Core

Section: Code Analysis and Metrics · A set of IDE plugins and rules that provide security "linting" capabilities.

SlowScore 70

Bandit

Python Code Quality Authority - Find common security vulnerabilities in Python code.

In 6 listsDetails

ESLint

JS Foundation - Linting tool for JavaScript with multiple security linting rules available.

In 6 listsDetails

Bearer

Open-Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.

In 6 listsDetails

SonarQube

SonarQube empowers development teams with a code quality and security solution that deeply integrates into your enterprise environment; enabling you to deploy clean code consistently and reliably. SonarQube provides a free and open source Community Build.

In 6 listsDetails

Brakeman

Justin Collins - Static analysis tool which checks Ruby on Rails applications for security vulnerabilities.

In 6 listsDetails

Git Secrets

Prevents you from committing passwords and other sensitive information to a git repository.

In 5 listsDetails

Semgrep

A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.

In 4 listsDetails

roslyn-analyzers

Diagnostic analyzers developed by the Roslyn team. Initially developed to help flesh out the design and implementation of the static analysis APIs. The analyzers cover code quality, .NET Core, desktop .NET Framework, comments in code, and more.

In 4 listsDetails