@AppThreat

Top repositories

1

dep-scan

Fully open-source security audit for project dependencies based on known vulnerabilities and advisories. Supports both local repos and container images. Integrates with various CI environments such as Azure Pipelines, CircleCI and Google CloudBuild. No server required!
Python
391
star
2

sast-scan

Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure DevOps, Google CloudBuild, VS Code and Visual Studio. No server required!
Python
143
star
3

vulnerability-db

Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm.
Python
57
star
4

atom

Atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.
Rust
44
star
5

cve_feeds

Download CVE feeds from NVD and GitHub
Python
19
star
6

joern-lib

Python library for code analysis with CPG and Joern
Jupyter Notebook
12
star
7

blint

BLint is a Binary Linter to check the security properties, and capabilities in your executables. It is powered by lief.
Python
10
star
8

sast-scan-action

GitHub action for performing SAST scanning using various oss tools such as gitleaks, bandit, findsecbugs etc
8
star
9

dep-scan-action

Fully open-source security audit for project dependencies based on known vulnerabilities and advisories. No server required!
7
star
10

vuln-list

Subset of https://github.com/aquasecurity/vuln-list suitable for dep-scan
7
star
11

cpggen

Generate CPG for multiple languages for code and threat analysis
C#
7
star
12

threat-db

A graph database for components, vulnerabilities and threats powered by dgraph
Python
5
star
13

hub_scan

Scan reports for popular docker hub and gcr images
Shell
4
star
14

atom-tools

Collection of tools for use with AppThreat/atom.
Python
3
star
15

atom-samples

Collection of atom, data-flow, and usage slices for appthreat/atom.
2
star
16

docs

Docs that are published at https://appthreat.io
2
star
17

cdxgen-docs

Documentation repo for CycloneDX Generator (cdxgen)
1
star
18

blint-action

Action to run BLint, the binary linter.
1
star
19

scan-reports

Library for producing gorgeous html reports from AppThreat scan results. Compatible with SARIF and grafeas format.
HTML
1
star
20

cve-annotations

UNUSED: Community powered annotations for CVE to identify source, sink, exploits and other information.
1
star
21

rosa

An experiment that looks very promising so far.
Python
1
star
22

depscan-bin

Binary builds for dep-scan - The Dependency Scanner
1
star
23

vulpy

Vulnerable Python Application To Learn Secure Development
Python
1
star