这是indexloc提供的服务,不要输入任何密码
Skip to content

Enhance your workflow with extensions

Tools from the community and partners to simplify tasks and automate processes

    Code Scanning Ready actions

    Static analysis, dynamic analysis, container scanning, linting, and fuzzing tools that integrate with GitHub Code Scanning SARIF Upload

    Combine all available linters to automatically validate your sources without configuration

    mobsfscan

    Action

    mobsfscan is a SAST that can find insecure code patterns in your Android and iOS source code

    Execute Flawfinder to scan source code for vulnerabilities

    checks if your Node.js installation is vulnerable to known security vulnerabilities

    Scan your projects with Qodana on GitHub. Docs: https://jb.gg/qodana-github-action

    image/svg+xml

    Run security analyzers

    ghascompliance

    Runs Semgrep with all rules from semgrep-rules-manager

    image/svg+xml

    PSRule

    Action

    Run rules in a GitHub repository

    Check for vulnerabilities in your container image

    Code-Pathfinder open-source alternative to CodeQL

    image/svg+xml

    Scalable and interprocedural C# code analyzer for detecting race condition, null pointer derefs and resource leaks

    GitHub Action for performing differential scans using ShellCheck linter

    Run tfsec against terraform code base and upload the sarif output to the github repo

    Scans your code for violations using Salesforce Code Analyzer, uploads results as an artifact, and creates a job summary

    Runs tfsec and outputs any failures

    Simplify Checkmarx Scanning of source code along with Result consumption leveraging Checkmarx CxFlow solution

    Find security vulnerabilities in your PHP codebase with Psalm, a free and open-source tool created by Vimeo

    Add flair to your infrastructure repositories with Terrafetch

    PMD

    Action

    Execute PMD static code analysis