image.png

SAST (Static Application Security Testing)

Semgrep (Python, JavaScript, Java, Go & more) + правила:  XSS / DOM-based XSS

**Horusec (for C#, Java, Kotlin, Python, Ruby, Golang, Terraform, Javascript, Typescript, Kubernetes, PHP, C, HTML, JSON, Dart, Elixir, Shell, and Nginx)**

🐻 **Bearer (for JavaScript, TypeScript, Ruby, and Java stacks)**

Terrascan (by Tenable - K8, Docker, Cuber, CFT, ARM etc)

Trivy (Repos, Containers, Kuber)

Brakeman (for Ruby)

Bandit (for Python)

**FindBugs (for Java)**

**Kubesec (for Kubernetes)**

Mate (for C/C++)

**CodeQL by GitHub**


DAST (Dynamic Application Security Testing)

Untrusted TypesPostMessage tracker


Info