govulncheck
Find and fix vulnerable dependencies with govulncheck
Semgrep is a highly configurable static analysis tool. I find its AI-assisted multimodal detection for SAST, SCA, and secrets scanning provides high signal for code security.
Visit semgrep.dev →