AppSecNews
SAST Open source Established

Horusec

by Zup Innovation

An open-source CLI that orchestrates a set of language-specific security scanners in containers and merges their findings into one report.

Visit github.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Horusec in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current maintenance status of the project: confirm activity in the repository before adopting
  • Exact list of bundled analyzers, which changes over time: confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Horusec is an orchestrator. It inspects a project directory, works out which languages and file types are present, and then runs the appropriate open-source analyzers, each pulled as a container image: gosec for Go, Bandit and Safety for Python, npm and yarn audit for JavaScript dependencies, Brakeman for Ruby, Semgrep for several languages, Gitleaks and its own entropy-based checks for secrets, Trivy for container and dependency issues, and several others. It also includes first-party analyzers written by the project for languages where no convenient open-source option existed.

Output from all of those tools is normalized into a single report with a common severity scale, deduplicated where the same issue is reported twice, and written as JSON, SARIF, text or a summary table. A false positive and risk acceptance list keyed by finding hash lets you suppress items persistently. An optional server-side component with a web dashboard adds multi-repository tracking, authentication and finding management on top of the CLI, deployable through containers or Helm.

Where it fits

The CLI runs in CI or on a developer machine and needs a container runtime available, since the analyzers ship as images. It is most attractive to teams who want breadth across a polyglot estate without wiring up a dozen scanners individually and reconciling a dozen output formats. Developers can run it, though the false positive volume from combining many tools usually means a security engineer decides which analyzers stay enabled.

Strengths

  • One command covers many languages plus dependencies, secrets and infrastructure files, which is genuinely convenient on polyglot repositories.
  • Normalized output and a persistent suppression list turn a pile of heterogeneous tool output into a workable queue.
  • Fully open source with a self-hostable dashboard, so nothing leaves your infrastructure.
  • Container-packaged analyzers mean you do not install and maintain each scanner's runtime dependencies yourself.

Limitations

  • Detection quality is entirely inherited from the wrapped tools, and their combined false positives arrive together. Expect substantial initial tuning.
  • Requires a container runtime in the scan environment, which complicates use in restricted CI runners and inside containerized builds.
  • Project activity has slowed, and a wrapper whose bundled analyzers fall behind upstream loses value quietly rather than visibly. Check the repository before committing to it.

Who it suits

Useful for polyglot teams that want open-source breadth from one entry point and are comfortable maintaining the tool themselves. Teams that need supported software, deep taint analysis, or assurance that analyzer versions stay current should look at a maintained commercial scanner or wire the individual upstream tools in directly.

Used Horusec? Recommend it under your own name and title.

Recommend this tool