Skip to content
#

code-scanning

Here are 42 public repositories matching this topic...

GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

  • Updated Oct 2, 2026
  • TypeScript

CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.

  • Updated Oct 1, 2026
  • TypeScript

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully offline, integrates with CI/CD, and outputs console, JSON, and SARIF reports.

  • Updated Sep 30, 2026
  • TypeScript

Add this topic to your repo

To associate your repository with the code-scanning topic, visit your repo's landing page and select "manage topics."

Learn more