Here's a list of github repos and tools that I believe are awesome and should be promoted and used.
- Semgrep - Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
- RegexPassive - Collection of regexp pattern for security passive scanning
- Secure Codebox - secureCodeBox (SCB) - continuous secure delivery out of the box