Semgrep is a fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Get started →.
Semgrep analyzes code locally on your computer or in your build environment: code is never uploaded.
Its rules look like the code you already write; no abstract syntax trees, regex wrestling, or painful DSLs. Here's a quick rule for finding Python print() statements, run it online in Semgrep's Playground by clicking the image:
Semgrep rule example for finding Python print() statements

The Semgrep ecosystem includes:
Semgrep - the open-source command line tool at the heart of everything (this project)
Semgrep CI - a specialized Docker image for running Semgrep in CI environments
Semgrep Playground - an online interactive rule builder for writing and sharing rules
Semgrep Registry - 2,000+ community-driven rules covering security, correctness, and performance bugs
Semgrep App - deploy, manage, and monitor Semgrep at scale with free and paid tiers.
Join 100,000 other developers and security engineers already using Semgrep at companies like Chef, Dropbox, Figma, HashiCorp, Snowflake, and Trail of Bits. Also check out tools powered by Semgrep!
Semgrep is developed and commercially supported by r2c, a software security company.
Language support
General availability
C# · Go · Java · JavaScript · JSX · JSON · PHP · Python · Ruby · Scala · TypeScript · TSX
The VMware vCenter Server APIs are organized around REST. For ease of use and security, REST builds on the standard web protocols HTTP and HTTPS, using the normal network ports 80 and 443, which are both open in most data centers, and uses standard HTTP response codes, authentication, and verbs.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project.
Black is the uncompromising Python code formatter. By using it, you agree to cede control over minutiae of hand-formatting. In return, Black gives you speed, determinism, and freedom from pycodestyle nagging about formatting. You will save time and mental energy for more important matters.
Blackened code looks the same regardless of the project you're reading. Formatting becomes transparent after a while and you can focus on the content instead.
Black makes code review faster by producing the smallest diffs possible.
Try it out now using the Black Playground. Watch the PyCon 2019 talk to learn more.
Wily is an application for tracking the complexity of Python code in tests and applications.
Wily uses git to go through each revision (commit) in a branch and run complexity and code-analysis metrics over the code. You can use this to limit your code or report on trends for complexity, length etc.

Ansible Lint is a command-line tool for linting playbooks, roles and collections aimed towards any Ansible users. Its main goal is to promote proven practices, patterns and behaviors while avoiding common pitfalls that can easily lead to bugs or make code harder to maintain.
Ansible lint is also supposed to help users upgrade their code to work with newer versions of Ansible. Due to this reason we recommend using it with the newest version of Ansible, even if the version used in production may be older.
As any other linter, it is opinionated. Still, its rules are the result of community contributions and they can always be disabled based individually or by category by each user.
Ansible Galaxy project makes use of this linter in order to compute quality scores for Galaxy Hub contributed content. This does not mean this tool is aimed only to those that want to share their code. Files like galaxy.yml, or sections like galaxy_info inside meta.yml help with documentation and maintenance, even for unpublished roles or collections.
The project was originally started by @willthames, and has since been adopted by the Ansible Community team. Its development is purely community driven, while keeping permanent communications with other Ansible teams.
Git hook scripts are useful for identifying simple issues before submission to code review. We run our hooks on every commit to automatically point out issues in code such as missing semicolons, trailing whitespace, and debug statements. By pointing these issues out before code review, this allows a code reviewer to focus on the architecture of a change while not wasting time with trivial style nitpicks.
As we created more libraries and projects we recognized that sharing our pre-commit hooks across projects is painful. We copied and pasted unwieldy bash scripts from project to project and had to manually change the hooks to work for different project structures.
We believe that you should always use the best industry standard linters. Some of the best linters are written in languages that you do not use in your project or have installed on your machine. For example scss-lint is a linter for SCSS written in Ruby. If you’re writing a project in node you should be able to use scss-lint as a pre-commit hook without adding a Gemfile to your project or understanding how to get scss-lint installed.
We built pre-commit to solve our hook issues. It is a multi-language package manager for pre-commit hooks. You specify a list of hooks you want and pre-commit manages the installation and execution of any hook written in any language before every commit. pre-commit is specifically designed to not require root access. If one of your developers doesn’t have node installed but modifies a JavaScript file, pre-commit automatically handles downloading and building node to run eslint without root.
Python bindings and code examples for using Varlink access to Podman Service
Der erste Teil der Artikelserie hat einen grundlegenden Überblick über Podman vermittelt, während der zweite Teil die Bausteine eines Linux-Containers und Sicherheitskonzepte von Podman genau beleuchtete, insbesondere die Ausführung ohne Root. Der dritte und letzte Teil der Artikelserie widmet sich den fortgeschrittenen Anwendungsfällen von Podman, angefangen bei der automatischen Generierung von Systemd-Services bis zur Container-Ausführung auf einem anderen System.
The holy cow of servers.
Ranch is a socket acceptor pool for building awesome TCP and TLS servers
Small, fast, modern HTTP server.
Cowboy is the ultimate server for the modern Web with support for Websocket, HTTP/2 and REST.
Virtual clusters are fully working Kubernetes clusters that run on top of other Kubernetes clusters. Compared to fully separate "real" clusters, virtual clusters do not have their own node pools. Instead, they are scheduling workloads inside the underlying cluster while having their own separate control plane.
Cluster API is a Kubernetes sub-project focused on providing declarative APIs and tooling to simplify provisioning, upgrading, and operating multiple Kubernetes clusters.
Started by the Kubernetes Special Interest Group (SIG) Cluster Lifecycle, the Cluster API project uses Kubernetes-style APIs and patterns to automate cluster lifecycle management for platform operators. The supporting infrastructure, like virtual machines, networks, load balancers, and VPCs, as well as the Kubernetes cluster configuration are all defined in the same way that application developers operate deploying and managing their workloads. This enables consistent and repeatable cluster deployments across a wide variety of infrastructure environments.
Clavier+ is a Windows utility that allows to create keyboard shortcuts involving almost any key, including the Windows keys, to launch programs, write text, open websites, ...
You always launch the same programs, navigate to the same websites? Create a simple shortcut to do it quicker.
Tired of writing your E-mail address? Create a universal keyboard shortcut to write it: it will work under Word, Excel, and your favorite Internet browser!
Clavier+ allows to associate actions to keyboard shortcuts.
Features:
-
Global shortcuts, available in almost any software.
-
Lauching a program or writing text with a single keystroke.
-
Small, portable, and fast: just an EXE of less than 200 Kb, no data in the Registry, setup program not required.
The Rockchip RK3568-powered NanoPi R5S SBC with two 2.5GbE ports, one Gigabit Ethernet port, and M.2 NVMe storage is now available for $59, or $75 with a metal enclosure.
As previously mentioned, the mini router board is equipped with 2GB RAM, 8GB eMMC flash, two USB 3.0 ports, as well as an HDMI output for people wanting to make use of the Rockchip RK3568 processor’s multimedia capabilities, or simply have a user interface on a monitor.

A module for working with LDAP from Elixir
Guardian is a token based authentication library for use with Elixir applications.
Guardian remains a functional system. It integrates with Plug but can be used outside of it. If you're implementing a TCP/UDP protocol directly or want to utilize your authentication via channels in Phoenix, Guardian can work for you.
The core currency of authentication in Guardian is the token. By default JSON Web Tokens are supported out of the box but you can use any token that:
Has the concept of a key-value payload
Is tamper proof
Can serialize to a String
Has a supporting module that implements the Guardian.Token behaviour
You can use Guardian tokens to authenticate:
Web endpoints (Plug/Phoenix/X)
Channels/Sockets (Phoenix - optional)
Any other system you can imagine. If you can attach an authentication token you can authenticate it.
Tokens should be able to contain any assertions (claims) that a developer wants to make and may contain both standard and application specific information encoded within them.
Guardian also allows you to configure multiple token types/configurations in a single application.
Peace of mind from prototype to production
Build rich, interactive web applications quickly, with less code and fewer moving parts. Join our growing community of developers using Phoenix to craft APIs, HTML5 apps and more, for fun or at scale.

This is the default scripted installation you’ll encounter on the official Arch Linux Archinstall package as well as the unofficial ISO found on https://archlinux.life. It will guide your through a very basic installation of Arch Linux.
The installer has two pre-requisites:
A Physical or Virtual machine to install on
An active internet connection prior to running archinstallFederbein Typ 641 Competition Art-Nr.: 641-0485-00 (ca 830€)
Bei diesem Federbein ist der Ausgleichsbehälter an einer Stahlflexleitung angebracht. So wird es zur idealen Alternative für Straßenmotorräder mit Platzproblemen. Der flexible Schlauch ermöglicht eine Anbringung des Ausgleichsbehälters dort, wo Platz ist - z.B. am Rahmenheck, wo Luftströmungen des Fahrtwinds für Kühlung sorgen. Auch die Einstellknöpfe für den Low- und High-Speed- Bereich der Druckstufe, jeder in 22 Stufen einstellbar, sind gut von außen erreichbar. Die Zugstufe kann durch ein offenes Bleedsystem 22-fach und die Federbasis stufenlos justiert werden.
Produkt kann von der Abbildung abweichen.
Federvorspannung, Druckstufe sowie Zugstufe einstellbar.



