Tools & Licenses
The vision behind GuardRails is to make security available to all. GuardRails comes with a growing number of internal security tools, and we are always working on curating and improving security rules to the highest quality levels. GuardRails also leverages the best security tools from the open-source community. These security tools power our many of our security engines. Our expert team configures the tools and carefully tunes the rule-set. With GuardRails you can use these tools across your repositories within minutes.
GuardRails only exists because we are standing on the shoulders of giants. This page acknowledges these giants. We are deeply grateful for their work and are working towards a model where we can give back and support them as well.
Apex
C/C++
Dotnet
Elixir
Golang
Java
Javascript
- ESLint - MIT
- NPM Audit - Artistic-2.0
- Retire.js - Apache-2.0
- NodeJsScan - GPL-3.0
- Semgrep - Javascript - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
Kubernetes
Mobile
Supporting Android/iOS/Windows mobile applications
PHP
- phpcs-security-audit - GPL-3.0
- Semgrep - PHP - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
Python
- Bandit - Apache-2.0
- Safety - MIT
- Semgrep - Python - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
Ruby
- Brakeman - MIT
- GuardRails leverages Brakeman v4.3.1. The latest release before the license change and acquisition by Synopsis.
- Bundler Audit - GPL-3.0
- Rubocop - MIT
Solidity
Terraform
TypeScript
Generic
- Detect-Secrets - Apache-2.0
- Semgrep - General - [LPGL-2.1](https://github.com/returntocorp/semgrep/blob/develop/LICENSE
- KICS - Apache-2.0
- Covers a lot of different Infrastructure as Code formats such as Ansible, Terraform, CloudFormation, Azure Resource Manager, Google Deployment Manager, Kubernetes and others.