Zagware Scanner is a free, open-source PR scanner — IaC misconfigurations, dependency vulnerabilities, and leaked secrets, in one container, with a single comment showing only what a PR actually introduces. Add the Git Tracking Platform when you need scan history, audit trails, and compliance reporting across your whole org.
Free, open-source, and self-hostable. Zagware Scanner runs on every pull request across GitHub, GitLab, Bitbucket, and Azure DevOps — combining KICS (IaC), Grype (SCA/dependency CVEs), and betterleaks (secrets) into one container, and diffing by fingerprint so you only see findings the PR introduces.
The optional backend for Scanner findings and your GitHub org's activity: scan history and trend charts, suppression audit trails, CIS GitHub Benchmark scans, real-time policy violation alerts, and change-management evidence for SOC-2 audits.
Zagware builds open-source security tooling for engineering teams. Zagware Scanner is free forever — no account, no lock-in — and detects IaC misconfigurations, vulnerable dependencies, and leaked secrets before they merge. The Git Tracking Platform is the paid backend teams add on when they need reporting, audit trails, and compliance evidence instead of just a PR comment.
We're also a software consultancy: platform integrations across GitHub, GitLab, Jira, ServiceNow, and Grafana, and bespoke internal tooling when off-the-shelf doesn't fit. Eng Team Reporter, pgbrowser, and PR Gate were built the same way we'll build yours — reach out if you need something custom.