All activity
![Eran Medan](https://ph-avatars.imgix.net/290488/original.jpeg?auto=compress&codec=mozjpeg&cs=strip&auto=format&w=48&h=48&fit=crop&frame=1)
The fully open source code analysis engine. Quickly analyze large code bases & fix security issues at scale.
Initiated by 10 rival security orgs, Opengreps promises to advance and commoditize static code security for the free use of all.
![Opengrep](https://ph-files.imgix.net/3f5fcb4e-c702-4782-8b2c-692104593637.png?auto=compress&codec=mozjpeg&cs=strip&auto=format&w=48&h=48&fit=crop&frame=1)
Opengrep
The open source code security engine
![Eran Medan](https://ph-avatars.imgix.net/290488/original.jpeg?auto=compress&codec=mozjpeg&cs=strip&auto=format&w=48&h=48&fit=crop&frame=1)
GitGoat is an open source tool built to enable DevOps and Engineering teams to design and implement a sustainable misconfiguration prevention strategy. It can be used to test products with access to GitHub repos without a risk to your production data.
![GitGoat](https://ph-files.imgix.net/344542dd-8f3a-4c3f-8d6c-3028c16a11a3.png?auto=compress&codec=mozjpeg&cs=strip&auto=format&w=48&h=48&fit=crop&frame=1)
GitGoat
Intentionally Misconfigured GitHub User + Repo + Teams Data
![Eran Medan](https://ph-avatars.imgix.net/290488/original.jpeg?auto=compress&codec=mozjpeg&cs=strip&auto=format&w=48&h=48&fit=crop&frame=1)
Software supply chain attacks have caught the security community off-guard. Arnica, starting with GitHub & Azure DevOps, addresses the two primary root causes:
1) 🪄 excessive permissions to developer tools
2) 🥸 lack of abnormal behavior detection
1) 🪄 excessive permissions to developer tools
2) 🥸 lack of abnormal behavior detection
Arnica
Behavior based software supply chain security