awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
snyk avatar

snyk/snyk

0
View on GitHub↗
5,586 Stars·686 Forks·TypeScript·25 Aufrufesnyk.io↗

Snyk

Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle.

The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patch vulnerabilities directly in project source code. It also features broker-based secure proxying, which establishes encrypted tunnels between private internal infrastructure and external services, allowing for secure scanning of internal assets without exposing sensitive network endpoints.

Beyond its core scanning capabilities, the platform provides extensive administrative and developer-focused tooling. This includes hierarchical tenant management for centralized policy enforcement, identity federation integration for automated user provisioning, and policy-driven security gating that can automatically block build processes or pull requests based on defined severity thresholds. The system also incorporates developer education modules to track and improve secure coding practices across engineering teams.

The platform is accessible via a command-line interface and programmatic APIs, enabling integration into existing development environments and CI/CD pipelines for continuous security monitoring and reporting.

Features

  • Application Security Testing Platforms - Provides a comprehensive security platform that identifies and remediates vulnerabilities in open-source dependencies, container images, infrastructure-as-code, and application source code.
  • Dependency Vulnerability Scanning - Identifies vulnerabilities in open-source packages and container images by analyzing project manifests across multiple languages.
  • Security Vulnerability Scanning - Scans application code, dependencies, and infrastructure configurations to detect security flaws and provide remediation guidance.
  • Hierarchical Account Structures - Organizes security management into a hierarchical model of tenants, groups, and projects for granular access control.
  • Developer Security Workflow Automation Tools - Integrates security scanning into development environments and CI/CD pipelines to enforce policy-driven remediation and automated gating.
  • Development Workflow Integrations - Connects security scanning into development tools and pipelines to provide real-time feedback and automated policy enforcement.
  • IDE Real-time Feedback - Provides real-time security feedback and remediation guidance directly within the code editor during development.
  • CLI Dependency Analyzers - Provides command-line tools that resolve and analyze project dependencies for security vulnerabilities.
  • Python Dependency Analyzers - Parses Python dependency manifests and lock files to build dependency trees and identify security vulnerabilities.
  • Security Fix Pull Requests - Automatically creates pull requests that update vulnerable dependencies to patched versions.
  • Security Policy Gates - Evaluates scan results against defined severity thresholds to automatically block build processes or pull requests that violate security standards.
  • Security Scanning Gates - Blocks pull requests or build pipelines based on vulnerability severity or fixability to prevent insecure code from being merged.
  • Vulnerability Merge Gates - Prevents merging code that introduces new security vulnerabilities by running automated scans in pull requests.
  • Security Scanning Integrations - Embeds automated vulnerability scanning into CI/CD pipelines to gate deployments and prevent insecure code from reaching production.
  • Pipeline Security - Enforces security reviews and automated vulnerability scanning within deployment workflows.
  • Security Testing Pipelines - Integrates security-specific tests into the continuous integration process to report or block deployments.
  • Security Gates - Blocks CI/CD pipelines based on security criteria and policy requirements.
  • Private Network Bridge Workers - Deploys bridge workers to connect internal source control systems to external security services through secure tunnels.
  • Vulnerability Auto-Remediation - Automatically applies security patches to software flaws based on scan results to reduce vulnerability backlogs.
  • Security Scanning Proxies - Establishes secure tunnels between private internal infrastructure and external security services to enable scanning without exposing network endpoints.
  • Vulnerability Ticket Creators - Automates remediation workflows by creating tickets for vulnerabilities and managing time-boxed ignores.
  • Dependency Vulnerability Scanners - Scans project dependency manifests to identify known security flaws in open-source libraries and packages.
  • Security Scan Policy Enforcers - Applies granular rules to ignore specific findings or block builds based on security status and policy enforcement.
  • License Compliance Tools - Evaluates open-source dependencies against defined policies to ensure project compliance with legal and organizational licensing requirements.
  • Enterprise SSO Authentication - Integrates with enterprise identity providers to enable centralized user authentication and single sign-on across the platform.
  • Private Repository Access Tools - Establishes secure bridges between private repository instances and the security platform to enable continuous scanning.
  • Secure Broker Networks - Deploys brokered connection clients to scan assets behind firewalls without exposing internal network credentials.
  • Secure Connection Managers - Establishes secure, encrypted tunnels between internal infrastructure and external security services for scanning.
  • Secure Tunneling Services - Establishes encrypted, private communication channels between private environments and external scanning services.
  • Security and Access Control - Provides centralized control over user roles, permissions, and single sign-on authentication to secure platform access.
  • Automated Security Remediation - Generates and submits pull requests to update vulnerable dependencies and apply security patches directly to project source code.
  • Security Coverage Policies - Specifies coverage criteria and security controls for software assets to identify gaps and ensure consistent scanning.
  • Security Scanning Broker Connections - Automates the configuration of secure broker connections to enable scanning of private code repositories via API.
  • Software Composition Analysis Tools - Scans project dependency manifests to detect known security flaws, license compliance issues, and generate software bills of materials.
  • Software Supply Chain Security - Identifies and remediates vulnerabilities in open-source dependencies and third-party packages throughout the software development lifecycle.
  • Source and Dependency Vulnerability Scanners - Scans source code and dependency manifests to identify vulnerabilities and generate software bills of materials.
  • Source Code Security Analysis - Performs static analysis on source code to identify security vulnerabilities and insecure coding patterns.
  • Source Code Vulnerability Scanning - Examines application code for security flaws using interfile analysis and standard library awareness.
  • Continuous Repository Scanners - Connects source code, container images, and infrastructure configurations for continuous security monitoring.
  • Pull Request Vulnerability Scanning - Analyzes code changes in incoming pull requests to prevent the introduction of new vulnerabilities.
  • Repository Import Scanners - Imports code repositories via SCM integrations to enable continuous security scanning and vulnerability detection.
  • Static Analysis Security Testing - Analyzes application source code across multiple programming languages to detect security flaws and insecure coding patterns.
  • User Access Management - Controls user permissions and account lifecycles by mapping identity provider roles to internal access levels.
  • Container Image Vulnerability Scanners - Examines container images for vulnerabilities in base images and installed packages to minimize the attack surface.
  • Vulnerability Prioritization - Ranks identified flaws based on risk scores and severity levels to focus remediation efforts on the most critical threats.
  • Static Analysis Engines - Parses source code and dependency manifests using language-specific rules to identify security vulnerabilities and insecure coding patterns.
  • Group-Wide Security Policy Configurations - Centralizes the management of security scanning rules for code, dependencies, and infrastructure at the organizational level.
  • Security Severity Build Gates - Enforces CI/CD pipeline failures based on configurable vulnerability severity thresholds to prevent insecure code from reaching production.
  • Static Code Analysis - Performs automated scanning of source code to detect security vulnerabilities and coding flaws without executing the program.
  • Agentic Workflow Orchestration - Coordinates automated tasks and AI-driven remediation logic to systematically reduce security backlogs across the software development lifecycle.
  • Production Monitoring Stacks - Tracks snapshots of deployed software components to provide ongoing visibility and alerting for vulnerabilities in production environments.
  • Product Security Question Answerers - Provides instant, context-aware answers to security queries using a curated knowledge base of documentation.
  • Source Control Management - Connects code repositories to centralize security scanning and automate vulnerability remediation across organizational units.
  • Vulnerability Notifications - Sends alerts via email or messaging platforms regarding vulnerabilities and project status updates to keep teams informed.
  • Invitation Cancellations - Cancels outstanding invitations to prospective members to prevent unauthorized access.
  • Organization Join Requests - Allows users to submit requests to join organizations, triggering administrative approval workflows.
  • Member Permission Modifiers - Modifies assigned roles for organization members to adjust their access privileges within the platform.
  • Member Removers - Revokes user access by removing members from organizations to prevent further interaction with resources.
  • Organization Invitations - Invites new or existing users to an organization and assigns them specific roles to control their access level.
  • Cross-Organization Asset Management - Provides a centralized interface to view, filter, and track all software assets and projects across the organization.
  • Source Connection Removals - Disconnects organizational integrations from broker connections to stop data flow between the platform and external services.
  • Analysis Report Aggregators - Consolidates vulnerability status data across multiple organizations into a single view to provide visibility into the entire group.
  • Dependency Graph Resolvers - Maps and traverses relationships between project modules to understand dependency structures.
  • Package Registry Integrations - Integrates with private package registries to resolve dependencies and block insecure packages during builds.
  • Infrastructure Scanning - Imports and scans infrastructure-as-code configuration files to identify security risks before deployment.
  • Security Platform Integrations - Facilitates connecting private repository hosts to the platform for automated security scanning.
  • Git Repository Integrators - Integrates with Git repositories to trigger automated security scans whenever code changes are pushed.
  • Integrated Development Environment Plugins - Integrates security scanning directly into development environments to provide real-time visibility.
  • Monorepo Workspace Scanning - Discovers and scans multiple sub-projects within monorepo structures using native package manager workspace configurations.
  • Programmatic Scanning APIs - Provides programmatic interfaces for triggering security assessments and processing results within automated development pipelines.
  • Source Control Imports for Scanning - Manages connections to external source control repositories to enable continuous security oversight.
  • Pip Project Scanners - Analyzes Python requirements files to identify vulnerabilities in project dependencies.
  • CLI Scanning Interfaces - Executes granular security tests on code and dependencies directly within build pipelines to identify and block insecure deployments.
  • Remediation Campaigns - Groups vulnerabilities by type to systematically eliminate entire classes of security flaws across the development lifecycle.
  • Source Code Repositories - Links version control systems to the platform to automate security scanning of code and dependencies.
  • Version Control Integrations - Connects to code repositories to perform automated scans and suggest dependency upgrades via pull requests.
  • Vulnerability Fix PR Generators - Generates pull requests to fix vulnerable dependencies and provides guidance for upgrading managed packages.
  • External Service Connection Management - Manages authenticated links between internal infrastructure and external services for secure data exchange.
  • Security Posture Dashboards - Aggregates vulnerability data, usage metrics, and incident assessments into centralized dashboards for compliance management.
  • Agent-Based Connectivity - Deploys multiple connection instances in containerized environments to bridge internal services with scanning platforms.
  • Container Registry Scanning - Imports container images from registries to perform recurring security scans and identify vulnerabilities within the container environment.
  • Containerized Environment Monitors - Tracks container images and deployed applications to alert on newly discovered vulnerabilities in production environments.
  • Infrastructure Configuration Validations - Validates infrastructure-as-code templates and container configurations to detect security misconfigurations before deployment.
  • Infrastructure Scanning - Scans container images and infrastructure-as-code files to identify security risks before deployment.
  • Security Automation Workflows - Embeds security scanning into development environments and build pipelines to enable programmatic security testing.
  • Version Control Integration - Links cloud projects to specific version control repositories to monitor codebases for vulnerabilities.
  • License Compliance Detectors - Detects unapproved open-source licenses in project dependencies and provides alerts with policy instructions for resolution.
  • Security Education - Delivers interactive lessons on vulnerability mitigation and security best practices across various technology stacks.
  • Command-Line Broker Configurators - Executes interactive workflows to create, retrieve, update, and delete infrastructure connections, credentials, and deployment settings.
  • Redundant Broker Deployments - Supports high-availability deployments by running redundant connection agents across separate hosts.
  • Private Network Connectivity - Facilitates secure communication between private infrastructure and external services using local credential references.
  • Vulnerability Suppressions - Excludes specific identified issues from future scan results with justifications and expiration dates for periodic review.
  • Access Provisioning - Manages the automated onboarding and provisioning of new users to the platform via single sign-on workflows.
  • Access Token Management - Generates and manages authentication tokens for programmatic access to security services and automated workflows.
  • Automated Secret Rotation - Automates the generation, replacement, and revocation of service account secrets to maintain secure authentication.
  • AI Security Posture Management - Monitors and governs artificial intelligence systems, including models and data sources, to ensure security and compliance.
  • Concurrent Session Restrictions - Enforces automatic logout for inactive users to prevent unauthorized access to unattended accounts.
  • Credential Management Integrations - Registers and references sensitive authentication tokens to enable secure automated security scanning and data synchronization.
  • Request Access Restrictions - Limits external service access to pre-approved data requests to ensure only necessary information is retrieved.
  • Granular Access Controls - Configures granular permissions and custom roles to manage security policies and reports while restricting access to sensitive settings.
  • Vendor Role Restrictions - Defines granular permissions for service accounts to limit their scope to specific monitoring and data collection tasks.
  • Credential Reference Sharing - Reuses integration tokens and broker configurations across multiple organizational units to simplify access control.
  • Identity Provider Role Mapping - Synchronizes user roles from identity providers during authentication to automatically provision access levels.
  • Infrastructure as Code Security - Scans configuration files and container images to detect security misconfigurations and vulnerabilities before deployment to production environments.
  • Multi-Tenant Hierarchy Organizers - Groups and categorizes security targets into a hierarchy of tenants, groups, and organizations to manage access and reporting.
  • Organization-Based Access Controls - Assigns users to specific groups and organizations dynamically based on identity provider attributes to automate provisioning.
  • Organization Structure Alignments - Groups and organizes users into hierarchical units to facilitate collaboration and manage security policies across different teams.
  • Execution Capability Restrictions - Prevents users from executing commands that push project snapshots to the platform to keep sensitive data local.
  • Personal Access Tokens - Provides mechanisms for generating and managing personal access tokens to authorize local development environments and automated pipelines.
  • Private Repository Ingestion Services - Establishes secure bridges to private repositories for vulnerability analysis without exposing internal infrastructure.
  • Private Network Security - Establishes secure tunnels between internal infrastructure and external services to scan private repositories without exposing sensitive network traffic.
  • Security Scan Organizers - Groups software projects into logical units to manage security policies, scan settings, and vulnerability notifications for specific teams.
  • Programmatic User Provisioning - Automates the assignment of roles and organizational access for users via an interface before their initial login.
  • Continuous Monitoring - Tracks imported projects over time to detect newly disclosed vulnerabilities and alert users to changes in security posture.
  • Role-Based Access Control - Implements role-based access control by assigning permission sets to users to restrict or expand actions at different levels.
  • User Role Authentication - Maps functional responsibilities to system capabilities by defining custom user roles and granular access permissions.
  • Group Role Assignments - Assigns administrative or standard member roles to users within a group to control their permissions and visibility.
  • Organization Role Assignments - Assigns users to specific organizations with defined roles to manage access levels upon authentication.
  • Tenant-Wide Role Assignments - Assigns specific roles to users within a tenant to control their visibility and administrative permissions over groups.
  • SAML Authentication - Verifies user identities through SAML providers to allow secure access with corporate credentials.
  • Network Access Configurators - Manages proxy and firewall configurations to enable secure, encrypted communication between internal infrastructure and security services.
  • Docker-Based Secure Proxy Deployments - Deploys secure proxy clients within clusters to connect internal systems to the security platform.
  • Java Dependency Scanners - Parses Java project files to identify production dependencies and build comprehensive trees for security analysis.
  • Language Scanning Rules - Defines organization-wide settings for dependency resolution, including scope exclusions and registry access for specific project types.
  • Pipenv Project Scanners - Analyzes Pipenv lock files and environment configurations to identify vulnerabilities in project dependencies.
  • Poetry Project Scanners - Inspects Poetry manifest and lock files to identify vulnerabilities in project dependencies.
  • Python Dependency Scanners - Analyzes Python dependency trees to detect known vulnerabilities and license compliance issues across various language versions.
  • Rust Dependencies - Scans Rust crate dependencies for known security vulnerabilities by testing SBOM documents or querying the package API.
  • TypeScript Dependencies - Identifies vulnerabilities and license compliance issues in TypeScript projects by analyzing lockfiles and manifests.
  • Automated Triage - Automates the triage of security findings by adjusting severity levels or suppressing noise to focus on critical risks.
  • Security Control Exceptions - Provides mechanisms to override failed security checks or ignore specific vulnerabilities through authorized administrative actions.
  • Broker Token Generation - Generates authentication tokens required to establish secure communication between internal infrastructure and external services.
  • Multi-Target Security Scanners - Evaluates configuration files and container images to identify security risks and misconfigurations before deployment.
  • Service Account Management - Creates and deletes machine-based identities using OAuth credentials to programmatically authenticate with the platform via API.
  • Single Sign-On Integrations - Configures integrations with external identity providers to enable centralized single sign-on and access policy enforcement.
  • Incremental Security Checks - Focuses security analysis on changes introduced in pull requests to minimize developer friction during code reviews.
  • Ruby Static Analysis - Scans Ruby source code for security vulnerabilities using pattern matching and cross-file data flow analysis.
  • TypeScript Security Scanners - Performs static analysis on TypeScript source files to detect security vulnerabilities, including interfile analysis.
  • Critical Asset Identification - Allows assigning business criticality levels to software assets to prioritize security remediation efforts.
  • Private Key JWT Authenticators - Authenticates service accounts using signed JWTs verified against public endpoints to ensure secure programmatic access.
  • User Authentication Workflows - Integrates with identity providers to centralize user authentication and manage provisioning through automated workflows.
  • External User Provisioning - Automatically creates local user accounts based on data retrieved from an external identity provider.
  • Vulnerability Report Generation - Produces vulnerability reports in various formats to facilitate local review or integration into automated build pipelines.
  • Webhook Security - Routes webhook notifications through local gateways to enable secure scanning without exposing internal infrastructure.
  • Application Relationship Mappers - Visualizes security issues, software assets, and their interdependencies to provide context for vulnerability management.
  • License Compliance Reports - Identifies open-source licenses and copyright statements within projects to ensure legal compliance.
  • Dependency License Extractors - Tracks and displays all open-source dependencies and their associated license information across projects to ensure compliance.
  • Service Account Permissions - Limits the actions of automated pipeline accounts to scanning and reporting while preventing unauthorized source control modifications.
  • Project Metadata Tags - Applies custom labels to projects to enable granular filtering and reporting based on operational criteria.
  • Remediation Tracking - Generates reports to monitor the volume of resolved versus new issues, enabling teams to audit security adoption and identify patterns.
  • Software Bill of Materials Generators - Generates comprehensive software bills of materials to ensure supply chain transparency and compliance.
  • Administrative Activity Logs - Retrieves audit logs for user actions and administrative changes to maintain visibility and security compliance across the organization.
  • Organizational Unit Management - Creates and removes isolated workspaces to organize projects and replicate settings from existing environments to new ones.
  • User Account Administration - Automates the provisioning, role assignment, and removal of users and service accounts to maintain consistent access control.
  • Member Removal - Terminates user membership within groups to restrict access to associated organizational resources.
  • Read-Only Access Controls - Limits user permissions to viewing scan results and reports while preventing project modifications.
  • Dependency Management - Monitors and scans projects for dependency vulnerabilities.
  • Security and Compliance - Security platform for finding and fixing vulnerabilities.

Star-Verlauf

Star-Verlauf für snyk/snykStar-Verlauf für snyk/snyk

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Open-Source-Alternativen zu Snyk

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Snyk.
  • snyk/cliAvatar von snyk

    snyk/cli

    5,428Auf GitHub ansehen↗

    The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies, proprietary application code, container images, and infrastructure-as-code configuration files. It also serves as a platform management tool, allowing users to configure organizations, users, SSO, and reporting from the terminal rather than the web dashboard. The CLI integrates directly into development workflows, enabling scanning within IDEs, build pipelines, and version control systems. It implements static analysis with interfile data flow analysis to find complex security f

    TypeScriptmonitorsecuritysnyk
    Auf GitHub ansehen↗5,428
  • google/osv-scannerAvatar von google

    google/osv-scanner

    10,565Auf GitHub ansehen↗

    osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and container images against the Open Source Vulnerabilities database. It functions as a dependency remediation tool and can be integrated into custom Go applications as a programmable security library. The project distinguishes itself through a remediation workflow that includes an interactive terminal user interface and automated scripting for upgrading vulnerable packages in lockfiles and manifests. It employs call-graph reachability analysis to determine if vulnerable code is act

    Goscannersecurity-auditsecurity-tools
    Auf GitHub ansehen↗10,565
  • dependencytrack/dependency-trackAvatar von DependencyTrack

    DependencyTrack/dependency-track

    3,612Auf GitHub ansehen↗

    Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity

    Javaappsecbill-of-materialsbom
    Auf GitHub ansehen↗3,612
  • aboutcode-org/scancode-toolkitAvatar von aboutcode-org

    aboutcode-org/scancode-toolkit

    2,567Auf GitHub ansehen↗

    ScanCode Toolkit is a software composition analysis tool and scanning framework designed to identify open-source licenses and copyright statements in source code and binary files. It functions as an open-source license detector, a dependency vulnerability scanner, and a generator for standardized software bills of materials in SPDX and CycloneDX formats. The project is built as a plugin-based scanning framework, allowing the integration of custom detection logic, specialized analyzers, and modified scanning behaviors at runtime. It distinguishes itself through the ability to produce formal le

    Pythoncopyrightcopyright-scancyclonedx
    Auf GitHub ansehen↗2,567
Alle 30 Alternativen zu Snyk anzeigen→

Häufig gestellte Fragen

Was macht snyk/snyk?

Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle.

Was sind die Hauptfunktionen von snyk/snyk?

Die Hauptfunktionen von snyk/snyk sind: Application Security Testing Platforms, Dependency Vulnerability Scanning, Security Vulnerability Scanning, Hierarchical Account Structures, Developer Security Workflow Automation Tools, Development Workflow Integrations, IDE Real-time Feedback, CLI Dependency Analyzers.

Welche Open-Source-Alternativen gibt es zu snyk/snyk?

Open-Source-Alternativen zu snyk/snyk sind unter anderem: snyk/cli — The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies,… google/osv-scanner — osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and… dependencytrack/dependency-track — Dependency-Track is a software composition analysis tool and vulnerability management system designed to track… aboutcode-org/scancode-toolkit — ScanCode Toolkit is a software composition analysis tool and scanning framework designed to identify open-source… bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… ajinabraham/nodejsscan — nodejsscan is a static analysis security tool and vulnerability detection engine designed to scan Node.js source code…