DryRun Security

Security context as you code, without being a security expert.

Code security· 4.5·0 saves·Freemium

Quick facts

Best for
Code security
Pricing
Freemium
Editor rating
4.5 / 5
Community saves
0
DryRun Security screenshot 1

About DryRun Security

DryRun Security is an AI-powered tool designed to support developers by providing automated in-line security checks during the coding process. Aimed at implementing a 'security buddy' in your coding workflow, it reinspects every code change as a pull request taking place, enabling developers to work faster and more safely. Its core focus is in providing a 'security context' to the developers, assisting them in understanding the impact of the code changes they're making, right as a pull request is opened. DryRun Security uses a mechanism called 'Contextual Security Analysis' to examine each pull request, which assists in reducing the frustrations often caused by repetitive alerts or inaccurate results in many other security testing applications. The tool is designed to support a variety of languages and frameworks including Rails, Express, Golang, Python, Node.js, Next.js and Javascript, with more to be added. The security features examined include Authentication and Authorization, Sensitive Codepaths, Sensitive Functions, Authorship and Intent, and Code Brittleness. The tool provides quick installation as a GitHub App and fast security reviews for code changes to enable faster merging. Furthermore, it offers a protection layer for every source code repository in your organization, helps to increase the velocity of the development pipeline, and thus enhances developer productivity.

Pros

  • Automated in-line security checks
  • Supports multiple languages and frameworks
  • Hub App quick installation
  • Fast security reviews
  • Protects every code repository
  • Increases development pipeline velocity
  • Contextual Security Analysis
  • Reduced false positives
  • Examines Authentication and Authorization
  • Examines Sensitive Codepaths
  • Examines Sensitive Functions
  • Examines Authorship and Intent

Cons

  • Limited to Git
  • Hub repositories
  • Missing support for some languages
  • Limited accuracy details provided
  • Reliance on pull request workflow
  • Unknown performance on large projects
  • Potentially overgeneralized security analysis
  • Limited customization options
  • Lack of enterprise features
  • In beta, potential instability
  • Lack of detailed technical documentation

Pricing

Pricing model
No Pricing