preflight

Vulnerability scanner

A tool to verify scripts and executables against known vulnerabilities to prevent chain of supply attacks

preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.

GitHub

152 stars
6 watching
45 forks
Language: Go
last commit: almost 4 years ago
Linked from 2 awesome lists

devopsdevsecopsgolangsecurity

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
americanexpress/earlybirdA tool that scans source code repositories for sensitive data vulnerabilities and weak practices711
prevade/cloudjackChecks AWS accounts for subdomain hijacking vulnerabilities84
1n3/blackwidowA Python-based web application scanner that gathers OSINT and fuzz data to identify OWASP vulnerabilities on target websites.1,545
kathanp19/gaussrfA tool for identifying potential vulnerabilities in websites by fetching known URLs and filtering out ones with open redirects or SSRF parameters.168
spectralops/netzAutomated network scanner discovering internet-wide misconfigurations of network services.389
pyupio/safetyDetects known security vulnerabilities in Python dependencies and provides recommendations for remediation.1,758
sectooladdict/wavsepAn open-source tool for evaluating web application vulnerabilities by analyzing the separation of concerns in web applications.232
checkmarx/kicsA tool for detecting security vulnerabilities and compliance issues in infrastructure-as-code projects2,117
r0075h3ll/oralyzerA tool to identify vulnerabilities in web applications by probing for Open Redirections and other types of attacks.758
menkrep1337/xssconA tool designed to scan websites for Cross-Site Scripting (XSS) vulnerabilities214
moduscreateorg/beepAn account security scanner that detects vulnerabilities in online accounts by hashing credentials and checking against data breaches.157
hasecuritysolutions/vulnwhispererAutomates vulnerability scanning and reporting by integrating multiple scanners into a unified platform1,362
twelvesec/rootendA tool designed to automate the discovery and exploitation of security vulnerabilities in Unix systems.147
boostsecurityio/poutineDetects misconfigurations and vulnerabilities in software supply chains during build pipelines.239