act
Run your GitHub Actions locally 🚀
actions
A collection of GitHub Actions to accelerate your Gradle Builds on GitHub
AISVS
The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications.
ASVS
Application Security Verification Standard
AutoDispose
Automatic binding+disposal of RxJava streams.
claude-code-action
No description
claude-code-base-action
This repo is a mirror of the contents of base-action in https://github.com/anthropics/claude-code-action.
difftastic
a structural diff that understands syntax 🟥🟩
gitea
Git with a cup of tea! Painless self-hosted all-in-one software development service, including Git hosting, code review, team collaboration, package registry and CI/CD
gosec
Go security checker
gradle
Adaptable, fast automation for all
haskell-z3
Haskell bindings to Microsoft's Z3 API (unofficial).
infer
A static analyzer for Java, C, C++, and Objective-C
java-html-sanitizer
Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.
legitify
Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets
NullAway
A tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead
opengrep
🔎 Static code analysis engine to find security issues in code.
osx-abi-macho-file-format-reference
Mirror of OS X ABI Mach-O File Format Reference
owasp-mstg
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
pfff
pfff is mainly an OCaml API to write static analysis, dynamic analysis, code visualizations, code navigations, or style-preserving source-to-source transformations such as refactorings on source code.
proposal-dynamic-code-brand-checks
TC39 proposal that enables flexible brand checks before dynamic code loading
RIBs
Uber's cross-platform mobile architecture framework - Android Repository
scorecard
OpenSSF Scorecard - Security health metrics for Open Source
scorecard-action
Official GitHub Action for OpenSSF Scorecard.
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
semgrep-action
This project is deprecated. Use https://github.com/returntocorp/semgrep instead
setup-bun
Set up your GitHub Actions workflow with a specific version of Bun
smtml
An SMT solver frontend for OCaml
Vulnerable-Flask-App
Intentionally Vulnerable Flask app for use in Demos