Secrets & Software Supply Chain
Secrets & Software Supply Chain is the set of tools used to keep credentials out of code and to know what is inside the software you build and ship. It covers secret scanning in repos and pipelines, software composition analysis and SBOM-driven vulnerability matching, and policy checks on infrastructure-as-code before release. Tools here protect the path from source to production, not the runtime network or the end-user login box alone.

Snyk
Developer security platform for finding and fixing issues in application code, open-source dependencies, containers and infrastructure as code.
Application SecurityFreemium
Grype
Grype is a free open-source vulnerability scanner from Anchore used to find known flaws in container images, filesystems, and SBOMs for DevSecOps teams.

Dependency-Track
Dependency-Track is a free platform used to analyze SBOMs and track component and vulnerability risk in the software supply chain for AppSec teams.

Gitleaks
Gitleaks is a free open-source secret scanner used to detect hardcoded passwords, API keys, and tokens in git repos and files for security and dev teams.

Checkov
Checkov is a free static analysis tool used to find misconfigurations in infrastructure as code and open source packages for cloud and DevSecOps teams.

GitGuardian
GitGuardian detects and remediates leaked secrets across code, CI/CD and collaboration tools, with a free plan for small teams and paid business tiers.
Application SecurityFreemium
TruffleHog
TruffleHog finds and verifies leaked secrets across git, cloud storage and CI artefacts, with a free open-source scanner and commercial TruffleHog Enterprise.

Trivy
Aqua Security's open-source scanner for vulnerabilities, misconfigurations, secrets and SBOMs across containers, code, Kubernetes and cloud targets.

HashiCorp Vault
HashiCorp Vault provides identity-based secrets management for keys, passwords and certificates, with free Community and paid Enterprise or HCP options.
Identity & AccessFreemium
Semgrep
Semgrep is a fast, open-source static analysis engine that finds bugs and security issues in code with pattern rules and ready-made rule packs.