• Rufus
    • Choosing a Tool
    • Package Managers
    • Dotfiles
    • Choosing a Terminal
    • zsh and Starship
    • tmux
    • fzf
    • zoxide
    • hyperfine
    • ripgrep
    • fd
    • bat
    • eza
    • jq
    • ast-grep
    • MinerU
    • Docling
    • VS Code
    • Neovim
    • JetBrains IDEs
    • Editing Skills
    • Claude Code
    • GitHub Copilot
    • Cursor
    • Ollama
    • Freebuff
    • Graft
    • Codebase Memory MCP
    • Agency Agents
    • OpenMontage
    • HyperFrames
    • Composio
    • Exa
    • The Daily Git Workflow
    • GitHub CLI (gh)
    • Gitea
    • Forgejo
    • GitLab
    • lazygit
    • delta
    • hunk
    • pre-commit Hooks
    • curl
    • HTTPie
    • Bruno and Postman
    • Exposing a Local Server
    • Tailscale
    • AutoCLI
    • Docker
    • Docker Compose
    • Podman
    • Local Kubernetes
    • kubectl and k9s
    • Helm
    • Kustomize
    • cert-manager
    • Istio
    • Policy as Code
    • GitHub Actions
    • Jenkins
    • GitLab CI/CD
    • SonarQube
    • Nexus Repository
    • Harbor
    • Argo CD
    • Flux
    • AWS CodePipeline
    • Terraform
    • Ansible
    • Secrets Management
    • Trivy
    • Falco
    • Backstage
    • Prometheus
    • Grafana
    • Loki
    • OpenTelemetry
    • k6
    • Chaos Engineering
    • OpenCost
    • Semgrep
    • gitleaks
    • Sigstore
    • ZAP
    • Wazuh
    • Raycast (macOS)
    • PowerToys (Windows)
    • Make and Makefiles
    • cron and launchd
    • n8n
    • Zen Browser
    • Webapp Manager
    • Zathura
    • Obsidian
    • Joplin
    • Markdown
    • Mermaid
    • Excalidraw
    • GenOffice
    • BatiOffice
    • Railway
    • Fly.io
    • Vercel
    • Cloudflare Workers
    • PostgreSQL
    • Neon
    • Supabase
    • Upstash
    • Cloudflare R2
    • Clerk
    • Resend
    • Inngest
    • Meilisearch
    • PostHog
    • Sentry
    • Lemon Squeezy
    • Groble
    • Raphael
    • Krea
    • Magnific
    • Clipdrop
    • ElevenLabs
    • Gemini TTS
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Security
    On this page
      • The order that actually works
      • Where this stops
      • The order that actually works
      • Where this stops
    shield

    Security

    Finding problems in your code, secrets, dependencies, running app, and hosts — with tools a developer can run, not a separate department.

    policy

    Semgrep

    Static analysis with patterns that look like the code they match — thousands of ready rules, and your own in ten minutes.

    password

    gitleaks

    Catching an API key before it reaches Git history — and finding the ones already there.

    fingerprint

    Sigstore

    Signing artifacts without managing keys — keyless signatures, a public transparency log, and a verify step your cluster can enforce.

    radar

    ZAP

    Testing the running application from the outside — a proxy, a scanner, and a baseline scan you can put in CI.

    gpp_good

    Wazuh

    Open-source SIEM and host security monitoring — agents on your machines, one place to see what happened, and compliance reports you didn't …


    © 2026 Toolian. Built with Lotus Docs