Tools & Licenses
The vision behind GuardRails is to make security a commodity. GuardRails leverages the best security tools from the open-source community. These security tools power our engines. Our expert team configures the tools and carefully tunes the rule-set. With GuardRails you can use these tools across your repositories within minutes.
GuardRails only exists because we are standing on the shoulders of giants. This page acknowledges the giants. We are deeply grateful for their work.
Apex
C/C++
- flawfinder - GPL-2.0
- Semgrep - C - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
Dotnet
Elixir
Golang
Java
Javascript
- ESLint - MIT
- NPM Audit - Artistic-2.0
- Retire.js - Apache-2.0
- NodeJsScan - GPL-3.0
- Semgrep - Javascript - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
Kubernetes
Mobile
Supporting Android/iOS/Windows mobile applications
PHP
- phpcs-security-audit - GPL-3.0
- Semgrep - PHP - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
Python
- Bandit - Apache-2.0
- Safety - MIT
- Semgrep - Python - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
Ruby
- Brakeman - MIT
- GuardRails leverages Brakeman v4.3.1. The latest release before the license change and acquisition by Synopsis.
- Bundler Audit - GPL-3.0
- Rubocop - MIT
Rust
Solidity
Terraform
TypeScript
Generic
- Detect-Secrets - Apache-2.0
- GuardRails Internal Secret Detection Engine