Scan any public repo
Free. No login. Results in about three minutes.
12 scannersSAST + secrets + CVE + IaC~3 minutes
Allowed:github.comgitlab.comcodeberg.orggitea.com
Recent scans
Showing 1–20 of 100 · refreshed just now- github.com/infiniflow/ragflowF1334 findingsdone4d ago
- github.com/affaan-m/ECCF325 findingsdone17d ago
- github.com/codecrafters-io/build-your-own-xA0 findingsdone29d ago
- github.com/labuladong/fucking-algorithmA0 findingsdone32d ago
- github.com/peterkelly/captain-bible-reA274 findingsdone34d ago
- github.com/browser-use/browser-useF58 findingsdone35d ago
- github.com/gohugoio/hugoD125 findingsdone36d ago
- github.com/axios/axiosF138 findingsdone37d ago
- github.com/kubernetes-monitoring/kubernetes-mixinF80 findingsdone37d ago
- github.com/Sentinel-One/sizingF29 findingsdone37d ago
- github.com/Sentinel-One/sane-reportsF635 findingsdone37d ago
- github.com/cespare/xxhashF256 findingsdone38d ago
- github.com/oklog/ulidA115 findingsdone38d ago
- github.com/datawhalechina/happy-llmF569 findingsdone38d ago
- github.com/dgtlmoon/changedetection.ioF85 findingsdone38d ago
- github.com/ziadoz/awesome-phpA2 findingsdone38d ago
- github.com/yewstack/yewF311 findingsdone38d ago
- github.com/VSCodium/vscodiumF54 findingsdone38d ago
- github.com/0xAX/linux-insidesB9 findingsdone38d ago
- github.com/floating-ui/floating-uiF437 findingsdone38d ago
The full security platform is on its way
The free scanner above is live today. Private-repository scanning, dashboards, and CI policy gates for teams are in active development.
Private-repo scanning
Connect GitHub, GitLab, Gitea & Codeberg and scan private repositories on every push.
Dashboards & findings
Triage, dedupe, and track findings across repos and images over time — not one-off reports.
Policy gates in CI
Fail a build or block a deploy when a scan crosses your severity, license, or secrets policy.
Scheduled & continuous scans
Re-scan on a cadence and on new CVE disclosures so regressions surface without a manual run.
SBOM & provenance
Generate and store SBOMs, sign artifacts, and keep an auditable provenance trail per image.
SSO, roles & audit
Team workspaces with SSO, role-based access, and audit-log streaming for compliance.
Want early access? Email hello@socbox.cloudNo account needed to use the public scanner — it stays free.