Image Get
GitHub
MobSF
CDX Gen
Semgrep
Exploit Finder
Bandit
Discord
Checkov
Sobelow
DepsDev
stdout JSON
Slack
ZAP
SonarQube
Git
Snyk Docker
LLM
Credo
OSV Scanner
S3 Target
ElasticSearch
Knowledgebase
Custom Annotation
DefectDojo
Jira
Deduplication
Dependency Track
Golang Gosec
KICS
Dependency
PDF Document
Multitool Deduplication
Training
Golang Nancy
Kafka
Codeowners
MobSF Scan
Sentry
Linear
Policy
Github PR comments
Trufflehog
Standards
Trivy
Reachability
CodeQL
Image Get
GitHub
MobSF
CDX Gen
Semgrep
Exploit Finder
Bandit
Discord
Checkov
Sobelow
DepsDev
stdout JSON
Slack
ZAP
SonarQube
Git
Snyk Docker
LLM
Credo
OSV Scanner
S3 Target
ElasticSearch
Knowledgebase
Custom Annotation
DefectDojo
Jira
Deduplication
Dependency Track
Golang Gosec
KICS
Dependency
PDF Document
Multitool Deduplication
Training
Golang Nancy
Kafka
Codeowners
MobSF Scan
Sentry
Linear
Policy
Github PR comments
Trufflehog
Standards
Trivy
Reachability
CodeQL
Image Get
GitHub
MobSF
CDX Gen
Semgrep
Exploit Finder
Bandit
Discord
Checkov
Sobelow
DepsDev
stdout JSON
Slack
ZAP
SonarQube
Git
Snyk Docker
LLM
Credo
OSV Scanner
S3 Target
ElasticSearch
Knowledgebase
Custom Annotation
DefectDojo
Jira
Deduplication
Dependency Track
Golang Gosec
KICS
Dependency
PDF Document
Multitool Deduplication
Training
Golang Nancy
Kafka
Codeowners
MobSF Scan
Sentry
Linear
Policy
Github PR comments
Trufflehog
Standards
Trivy
Reachability
CodeQL
Image Get
GitHub
MobSF
CDX Gen
Semgrep
Exploit Finder
Bandit
Discord
Checkov
Sobelow
DepsDev
stdout JSON
Slack
ZAP
SonarQube
Git
Snyk Docker
LLM
Credo
OSV Scanner
S3 Target
ElasticSearch
Knowledgebase
Custom Annotation
DefectDojo
Jira
Deduplication
Dependency Track
Golang Gosec
KICS
Dependency
PDF Document
Multitool Deduplication
Training
Golang Nancy
Kafka
Codeowners
MobSF Scan
Sentry
Linear
Policy
Github PR comments
Trufflehog
Standards
Trivy
Reachability
CodeQL
Image Get
Codeowners
MobSF Scan
Linear
S3 Target
Kafka
Deduplication
DepsDev
Reachability
stdout JSON
Discord
Jira
DefectDojo
Sentry
Git
Dependency Track
CDX Gen
Checkov
KICS
Github PR comments
OSV Scanner
Standards
Training
MobSF
Knowledgebase
PDF Document
Exploit Finder
Dependency
SonarQube
LLM
Trivy
GitHub
Credo
Bandit
Semgrep
ZAP
Golang Nancy
Slack
Golang Gosec
Custom Annotation
ElasticSearch
Sobelow
CodeQL
Multitool Deduplication
Snyk Docker
Policy
Trufflehog
Image Get
Codeowners
MobSF Scan
Linear
S3 Target
Kafka
Deduplication
DepsDev
Reachability
stdout JSON
Discord
Jira
DefectDojo
Sentry
Git
Dependency Track
CDX Gen
Checkov
KICS
Github PR comments
OSV Scanner
Standards
Training
MobSF
Knowledgebase
PDF Document
Exploit Finder
Dependency
SonarQube
LLM
Trivy
GitHub
Credo
Bandit
Semgrep
ZAP
Golang Nancy
Slack
Golang Gosec
Custom Annotation
ElasticSearch
Sobelow
CodeQL
Multitool Deduplication
Snyk Docker
Policy
Trufflehog
Image Get
Codeowners
MobSF Scan
Linear
S3 Target
Kafka
Deduplication
DepsDev
Reachability
stdout JSON
Discord
Jira
DefectDojo
Sentry
Git
Dependency Track
CDX Gen
Checkov
KICS
Github PR comments
OSV Scanner
Standards
Training
MobSF
Knowledgebase
PDF Document
Exploit Finder
Dependency
SonarQube
LLM
Trivy
GitHub
Credo
Bandit
Semgrep
ZAP
Golang Nancy
Slack
Golang Gosec
Custom Annotation
ElasticSearch
Sobelow
CodeQL
Multitool Deduplication
Snyk Docker
Policy
Trufflehog
Image Get
Codeowners
MobSF Scan
Linear
S3 Target
Kafka
Deduplication
DepsDev
Reachability
stdout JSON
Discord
Jira
DefectDojo
Sentry
Git
Dependency Track
CDX Gen
Checkov
KICS
Github PR comments
OSV Scanner
Standards
Training
MobSF
Knowledgebase
PDF Document
Exploit Finder
Dependency
SonarQube
LLM
Trivy
GitHub
Credo
Bandit
Semgrep
ZAP
Golang Nancy
Slack
Golang Gosec
Custom Annotation
ElasticSearch
Sobelow
CodeQL
Multitool Deduplication
Snyk Docker
Policy
Trufflehog
Golang Nancy
Git
Dependency
CDX Gen
LLM
Kafka
Dependency Track
Deduplication
Trufflehog
MobSF
ZAP
Training
Knowledgebase
PDF Document
Sentry
Discord
Slack
Policy
Codeowners
Trivy
Exploit Finder
Reachability
GitHub
Golang Gosec
CodeQL
Checkov
Linear
Jira
Multitool Deduplication
SonarQube
Sobelow
S3 Target
Credo
Semgrep
DefectDojo
Snyk Docker
Image Get
stdout JSON
Standards
Github PR comments
OSV Scanner
ElasticSearch
Bandit
Custom Annotation
KICS
MobSF Scan
DepsDev
Golang Nancy
Git
Dependency
CDX Gen
LLM
Kafka
Dependency Track
Deduplication
Trufflehog
MobSF
ZAP
Training
Knowledgebase
PDF Document
Sentry
Discord
Slack
Policy
Codeowners
Trivy
Exploit Finder
Reachability
GitHub
Golang Gosec
CodeQL
Checkov
Linear
Jira
Multitool Deduplication
SonarQube
Sobelow
S3 Target
Credo
Semgrep
DefectDojo
Snyk Docker
Image Get
stdout JSON
Standards
Github PR comments
OSV Scanner
ElasticSearch
Bandit
Custom Annotation
KICS
MobSF Scan
DepsDev
Golang Nancy
Git
Dependency
CDX Gen
LLM
Kafka
Dependency Track
Deduplication
Trufflehog
MobSF
ZAP
Training
Knowledgebase
PDF Document
Sentry
Discord
Slack
Policy
Codeowners
Trivy
Exploit Finder
Reachability
GitHub
Golang Gosec
CodeQL
Checkov
Linear
Jira
Multitool Deduplication
SonarQube
Sobelow
S3 Target
Credo
Semgrep
DefectDojo
Snyk Docker
Image Get
stdout JSON
Standards
Github PR comments
OSV Scanner
ElasticSearch
Bandit
Custom Annotation
KICS
MobSF Scan
DepsDev
Golang Nancy
Git
Dependency
CDX Gen
LLM
Kafka
Dependency Track
Deduplication
Trufflehog
MobSF
ZAP
Training
Knowledgebase
PDF Document
Sentry
Discord
Slack
Policy
Codeowners
Trivy
Exploit Finder
Reachability
GitHub
Golang Gosec
CodeQL
Checkov
Linear
Jira
Multitool Deduplication
SonarQube
Sobelow
S3 Target
Credo
Semgrep
DefectDojo
Snyk Docker
Image Get
stdout JSON
Standards
Github PR comments
OSV Scanner
ElasticSearch
Bandit
Custom Annotation
KICS
MobSF Scan
DepsDev

Integrations

Do you need a new integration? We can build it.
See what's available out of the box
Git
Clones any git repository. Can be on GitHub, BitBucket, GitLab, Azure etc.
target
GitHub
Integrate with your GitHub PR and push events. Event-driven workflow executions.
target
Dependency
Accepts a pURL argument belonging to one of the supported types and generates a dependency file relevant to the type.
Homepage
target
S3 Target
Downloads an archive from an S3-compatible API.
target
Image Get
Download a remote image from any registry.
target
Bandit
Static application security testing for Python source code.
scanner
Checkov
Static code analysis for infrastructure as code. Finds misconfigurations that may lead to security or compliance problems. Policy as code.
scanner
Credo
Static code analysis tool for Elixir source code.
Homepage
scanner
CodeQL
Github CodeQL - semantic static analysis for code.
scanner
CDX Gen
Generates a CycloneDX SBOM from source code then sends to Dependency track.
scanner
Trufflehog
Scans code for secrets.
scanner
Sobelow
Static code analysis scanner for the Elixir Phoenix Framework.
scanner
Snyk Docker
Run Snyk For Docker.
scanner
OSV Scanner
Scans third party dependencies of multiple languages.
scanner
Dependency Track
Uploads CycloneDX SBOMs to Dependency Track.
scanner
KICS
Static analysis for infrastructure as code.
Homepage
scanner
Golang Gosec
Static analysis for Go code vulnerabilities.
scanner
ZAP
Dynamic application security scanner that analyses web applications for security issues.
scanner
Trivy
Scan for vulnerabilities and misconfigurations in code repositories, binary artifacts, container images and Kubernetes clusters.
scanner
Golang Nancy
Scans dependencies for Go projects.
scanner
SonarQube
Static analysis and Software Composition Analysis for your code. Uses SonarQube Cloud.
scanner
Semgrep
Static analysis for source code.
scanner
MobSF Scan
Static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Android XML, Swift and Objective C Code. Mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher. It scans code.
scanner
MobSF
Static analysis tool that can find vulnerabilities in your Android and iOS applications. It scans packaged application files.
scanner
Codeowners
Identifies a code owner for each finding.
enricher
DepsDev
Adds context from deps.dev for each third-party dependency.
Homepage
enricher
Training
Adds relevant training resources to findings.
enricher
Reachability
Performs a reachability check on a supplied repository using AppThreat/atom.
enricher
Deduplication
Compares multiple findings, removes duplicates and categorises them into issues, locations and vulnerabilities.
Homepage
enricher
Knowledgebase
Adds knowledge base information (e.g. OWASP Cheat Sheets) to findings.
enricher
Policy
Enforces security policies defined in OPA for each finding.
enricher
LLM
Adds information to findings using a language model.
enricher
Multitool Deduplication
Deduplicates findings from multiple tools.
enricher
Custom Annotation
Adds custom annotations to instances.
enricher
Standards
Adds security standard information to findings using OpenCRE.
enricher
Exploit Finder
Enricher component that searches Exploit-DB and Github for PoCs of exploits related to a specific CVE
enricher
PDF Document
Generates a detailed report into a PDF and uploads it to an S3-compatible bucket.
reporter
DefectDojo
Pushes findings to a DefectDojo vulnerability management instance.
reporter
stdout JSON
Prints findings to stdout in JSON format.
reporter
Slack
Pushes short finding alerts to Slack.
reporter
Discord
Pushes short finding alerts to Discord.
reporter
Linear
Pushes finding details tickets to Linear.
reporter
Github PR comments
Posts findings as comments on open Github Pull Requests.
reporter
Jira
Pushes finding details tickets to Jira.
reporter
Sentry
Creates events to a Sentry project for vulnerability findings.
reporter
ElasticSearch
Pushes findings to a remote ElasticSearch.
reporter
Kafka
Sends raw OCSF findings in proto format to a configured Kafka topic.
reporter

Ready to revolutionise your DevSecOps?

Get the most flexible ASPM in the world. Use Smithy and secure your code today.