HTTP/2 200
date: Thu, 31 Jul 2025 11:47:57 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"208a5d01edb925e5ec3c32a5b176a55b"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=KAXR2ZHFY2hnKwQlXmlmFSyZ1KWIIX5QzkzeDAzJGJk9ZR%2FcISMtqtTfFfdPaXKfvdcvQe5mPiapxh%2BPQecE5BMmCxxAqshYEHZT%2FZLFxFFTxMON2e5iNw0IZB5M7y1gNpdWO1CQAg7DhOrPghlfLlBQhn%2BpzQs2IxBf03PPdYV4mfGHOpzbLW53Y14lvvZbFF1HsDeFyBXI1TagniB%2Fd0rZp10qi%2BIWrucRO6U6vVysApvLbWzloJcj0HQQg4UjHPYweRggg%2F1dLsNTY8KhDQ%3D%3D--4zI225GMDXObJDs5--RklFRutOgWdYU8oIY4u%2Frg%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.1725817470.1753962477; Path=/; Domain=github.com; Expires=Fri, 31 Jul 2026 11:47:57 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Fri, 31 Jul 2026 11:47:57 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: 99CA:184B44:96E26D:B3FAE8:688B57ED
Checkmarx · GitHub
Checkmarx
Verified
We've verified that the organization Checkmarx controls the domain:
Pinned
Loading
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Open Policy Agent
2.4k
336
Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git
Go
96
25
A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.
CSS
297
80
If you are using a CI/CD platform that doesn’t yet have a dedicated Checkmarx plugin, please check this repository.
Groovy
10
19
Repositories
Showing 10 of 56 repositories
ast-vscode-extension
Public
The Checkmarx One Visual Studio Code plugin (extension) enables you to import results from a Checkmarx One scan directly into your VS Code console. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.
Checkmarx/ast-vscode-extension’s past year of commit activity
TypeScript
15
Apache-2.0
8
5
34
Updated Jul 31, 2025
kics
Public
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Checkmarx/kics’s past year of commit activity
ast-eclipse-plugin
Public
The CxAST Eclipse plugin enables you to import results from a CxAST scan directly into your IDE. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.
Checkmarx/ast-eclipse-plugin’s past year of commit activity
Java
4
Apache-2.0
12
1
5
Updated Jul 31, 2025
ast-cli
Public
A CLI project wrapping application security testing (AST) APIs
Checkmarx/ast-cli’s past year of commit activity
Go
53
Apache-2.0
26
5
27
Updated Jul 31, 2025
ast-visual-studio-extension
Public
The CxAST Visual Studio plugin enables you to import results from a CxAST scan directly into your IDE
Checkmarx/ast-visual-studio-extension’s past year of commit activity
C#
2
Apache-2.0
6
1
12
Updated Jul 31, 2025
Checkmarx/kics-cdk-validator-plugin’s past year of commit activity
TypeScript
7
Apache-2.0
3
1
5
Updated Jul 31, 2025
ast-teamcity-plugin
Public
The CxAST TeamCity plugin enables you to trigger SAST, SCA, and KICS scans directly from a TeamCity project.
Checkmarx/ast-teamcity-plugin’s past year of commit activity
Java
3
Apache-2.0
2
1
20
Updated Jul 31, 2025
Checkmarx/ast-github-action’s past year of commit activity
Shell
21
Apache-2.0
28
3
8
Updated Jul 31, 2025
Checkmarx/homebrew-ast-cli’s past year of commit activity
Ruby
2
0
0
0
Updated Jul 31, 2025
2ms
Public
Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git
Checkmarx/2ms’s past year of commit activity
Most used topics
Loading…
You can’t perform that action at this time.