Documentation
Scan with Docker locally or in CI — deps-cves (OSV/GHSA), Trivy, Semgrep, Syft, Gitleaks, and Checkov in one image, plus opt-in segrep-sast and segrep-sbom.
Start here
Scan any repo with Docker — local dev and CI in minutes.
Hosted app
Sign in for scan history, API access, and GitHub PR integration.
Product
Scanners
- segrep-sbom scannerOpt-in local SBOM scanner with optional Syft parity shadow
- segrep-vuln scannerOpt-in local vulnerability scanner with optional Trivy parity shadow
- segrep-dast scannerOpt-in local passive DAST scanner for deterministic runtime checks
- segrep-sast scannerOpt-in native Tree-sitter SAST engine and rule system
- segrep-license scannerOpt-in license compliance scanner with SPDX risk classification
- segrep-secrets scannerOpt-in native regex-based secret detection for API keys, tokens, and credentials
- segrep-iac scannerOpt-in local IaC misconfiguration scanner for Terraform, Kubernetes, and Dockerfiles
- segrep-cloud scannerOpt-in cloud security scanner for AWS, GCP, Azure credentials, IAM, and Terraform
- segrep-k8s scannerOpt-in Kubernetes manifest security scanner for RBAC, pod security, and deployment configs