Secure development tools
Code scanning, dependencies, Python tools and build automation.
Semgrep for mobile source-code security
Semgrep can identify selected security patterns in mobile source code.
Read the guideCodeQL for mobile code data-flow analysis
CodeQL contributes data-flow queries to code review. Make source and build coverage explicit; layers outside the analysis must not be assumed safe.
Read the guideSonarQube in mobile security development
SonarQube connects code-quality and security review to development workflows. Read reports in the context of the selected edition and supported analysis features.
Read the guideWhere Nuclei fits in mobile API testing
Nuclei automates template-based checks. In app protection work, it primarily assesses back ends and related services rather than on-device runtime defenses.
Read the guideGitleaks for secrets in mobile repositories
Gitleaks helps find secrets accidentally committed to source control. Removing a value may need to be followed by revocation and an investigation of its use.
Read the guideTruffleHog for secret discovery and verification
TruffleHog supports secret discovery and, where appropriate, validation.
Read the guideTrivy for mobile build-environment scanning
Trivy can assess dependencies and build environments used by mobile projects. Distinguish the selected scan mode from the components it actually examines.
Read the guideGrype for dependency vulnerability scanning
Grype links component inventories with known vulnerability information. A match still requires an assessment of whether the application is affected.
Read the guideSyft for software component inventories
Syft helps inventory software components. For mobile delivery, check native libraries and components introduced by protection as well as source dependencies.
Read the guideCycloneDX for mobile SBOM exchange
CycloneDX provides a standard ecosystem for sharing component and related security information.
Read the guideWhat OWASP Dependency-Check examines
Dependency-Check supports dependency risk assessment. Accurate package matching and the vulnerability's effect on real code paths are central to interpreting its reports.
Read the guideOSV-Scanner for dependency security
OSV-Scanner associates dependencies with vulnerability information. Verify that its input matches current lockfiles or the components actually distributed.
Read the guideAuditing Python tooling with pip-audit
pip-audit can assess dependencies used by Python mobile-analysis helpers. The environment that examines an application also needs security maintenance.
Read the guideBandit for Python security code review
Bandit finds selected security patterns in Python. It adds a review layer for file, network and secret handling in mobile-analysis scripts.
Read the guideRuff for dependable Python analysis scripts
Ruff improves Python code quality and consistency. Clean lint output does not prove that a cryptographic protocol or mobile security test is correctly designed.
Read the guidepytest for mobile security helper verification
pytest can verify security-helper behavior. Invalid packages, missing fields and verification failures deserve coverage alongside normal inputs.
Read the guideHypothesis for property-based Python testing
Hypothesis explores unexpected inputs through property-based tests. It produces useful evidence when mobile-verification helpers have clearly defined invariants.
Read the guidePython cryptography for verification tools
The cryptography library supports signing, verification and encryption helpers. Safe API selection must be paired with sound key management and protocol context.
Read the guideRequests for secure test clients
Requests is widely used in Python test clients. Configure certificate verification, timeouts, retries and secret-header logging deliberately.
Read the guideScapy for network protocol research
Scapy supports protocol research and controlled laboratory automation. Define authorization, collection limits and test scope before using it beyond the laboratory.
Read the guideYARA for mobile package pattern matching
YARA searches files for defined patterns. A match is an investigation input, not sufficient evidence of malicious behavior or failed protection.
Read the guidefastlane in a RASP delivery pipeline
fastlane automates mobile delivery steps. Design protection, signing and store-upload order together with trustworthy records and secret management.
Read the guideGradle for Android RASP integration
Gradle controls dependencies, variants and task order in Android protection integration. Acceptance must examine the final package as well as source configuration.
Read the guideXcode in the protected iOS build process
Xcode is central to iOS building, signing and diagnostics. Assess a security SDK against the final IPA, entitlement set and matching symbol archive.
Read the guideGitHub Actions for mobile security gates
GitHub Actions can connect security gates to delivery. Control untrusted contributions' access to release secrets and preserve the identity of approved artifacts.
Read the guide