Updates, guides, and thoughts on developer security scanning.
Segrep now ships deps-cves (OSV/GHSA), Syft, Gitleaks, and Checkov alongside Trivy and Semgrep — broader dependency, IaC, secrets, and SBOM coverage in every scan.
Segrep
Learn how Static Application Security Testing works, what vulnerabilities it finds, and how to integrate SAST into your CI/CD pipeline before code reaches production.
Segrep
One Docker image for dependency, SAST, secret, IaC, and SBOM scans — including OSV/GHSA dependency CVEs — locally, in CI, or with an optional hosted dashboard.
Segrep