Allstar is a GitHub App that continuously monitors GitHub organizations or repositories for adherence to security best practices. It detects security policy violations and creates an issue to alert the repository or organization owner. Allstar gives you finely tuned control over the files and settings that affect the security of your projects. You can choose which security policies to monitor at both the organization and repository level, and how to handle policy violations. You can also develop or contribute new policies. Allstar is developed under the OpenSSF organization.
FEATURES
SIMILAR TOOLS
Donate to your favorite open-source projects and charities using PayPal
Open source web application security scanner with 200+ vulnerability identification capabilities.
A list of vulnerable applications for testing and learning
A runtime threat management and attack path enumeration tool for cloud-native environments
Web inventory tool that captures screenshots of webpages and includes additional features for enhanced usability.
A tool that checks for hijackable packages in NPM and Python Pypi registries
Tool to identify and understand code-injection vulnerabilities in Windows 7 UAC whitelist system.
A Java based HTTP/HTTPS proxy for assessing web application vulnerability with various useful features.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.