Skip to content
@Checkmarx

Checkmarx

Pinned Loading

  1. kics kics Public

    Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

    Open Policy Agent 2.7k 381

  2. 2ms 2ms Public

    Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git

    Go 156 35

  3. capital capital Public

    A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.

    CSS 336 90

  4. ci-cd-integrations ci-cd-integrations Public

    If you are using a CI/CD platform that doesn’t yet have a dedicated Checkmarx plugin, please check this repository.

    Groovy 14 23

Repositories

Showing 10 of 70 repositories
  • harden-runner-action Public Forked from step-security/harden-runner

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

    Checkmarx/harden-runner-action's past year of commit activity
    TypeScript 0 Apache-2.0 125 0 0 Updated Sep 13, 2026
  • ast-cli Public

    A CLI project wrapping application security testing (AST) APIs

    Checkmarx/ast-cli's past year of commit activity
    Go 11 Apache-2.0 6 4 6 Updated Sep 11, 2026
  • kics Public

    Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

    Checkmarx/kics's past year of commit activity
    Open Policy Agent 2,699 Apache-2.0 381 157 159 Updated Sep 11, 2026
  • 2ms Public

    Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git

    Checkmarx/2ms's past year of commit activity
    Go 156 Apache-2.0 35 10 (2 issues need help) 10 Updated Sep 11, 2026
  • ast-vscode-extension Public

    The Checkmarx One Visual Studio Code plugin (extension) enables you to import results from a Checkmarx One scan directly into your VS Code console. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.

    Checkmarx/ast-vscode-extension's past year of commit activity
    TypeScript 19 Apache-2.0 10 10 20 Updated Sep 11, 2026
  • ast-azure-plugin Public

    The CxAST Azure DevOps plugin enables you to trigger SAST, SCA, and KICS scans directly from an Azure DevOps pipeline.

    Checkmarx/ast-azure-plugin's past year of commit activity
    TypeScript 8 Apache-2.0 6 9 20 Updated Sep 11, 2026
  • ast-eclipse-plugin Public

    The CxAST Eclipse plugin enables you to import results from a CxAST scan directly into your IDE. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.

    Checkmarx/ast-eclipse-plugin's past year of commit activity
    Java 4 Apache-2.0 12 2 4 Updated Sep 11, 2026
  • cx-agentic-ai Public

    Checkmarx Marketplace for agentic solutions

    Checkmarx/cx-agentic-ai's past year of commit activity
    Python 0 Apache-2.0 2 0 5 Updated Sep 10, 2026
  • ast-visual-studio-extension Public

    The CxAST Visual Studio plugin enables you to import results from a CxAST scan directly into your IDE

    Checkmarx/ast-visual-studio-extension's past year of commit activity
    C# 3 Apache-2.0 6 3 7 Updated Sep 10, 2026
  • Checkmarx/doss-github-actions-public's past year of commit activity
    0 0 0 1 Updated Sep 10, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.