bearer
Off-the-shelfData-flow static analysis over the artifact's own source code.
What it scans
Source code in JS/TS, Python, Ruby and related languages, tracing how data moves through the program.
What it catches
- Hardcoded secrets committed into source.
- Injection vulnerabilities.
- Unsafe data flows where sensitive data reaches a risky sink.
Source and provenance
Nerlo pins and publishes each scanner's provenance so you can verify it yourself. Every scan surfaces the source, version, and install command in its report.
- Kind
- Off-the-shelf
- Source channel
- github releases
- Pinned version
- 2.0.2
- License
- Elastic-2.0
- Source URL
- https://github.com/Bearer/bearer