Compare the Top Code Security Tools that integrate with GitHub as of September 2026 - Page 2

This a list of Code Security tools that integrate with GitHub. Use the filters on the left to add additional filters for products that have integrations with GitHub. View the products that work with GitHub in the table below.

  • 1
    CodeSonar

    CodeSonar

    CodeSecure

    CodeSonar employs a unified dataflow and symbolic execution analysis that examines the computation of the complete application. By not relying on pattern matching or similar approximations, CodeSonar's static analysis engine is extraordinarily deep, finding 3-5 times more defects on average than other static analysis tools. Unlike many software development tools, such as testing tools, compilers, configuration management, etc., SAST tools can be integrated into a team's development process at any time with ease. SAST technologies like CodeSonar simply attach to your existing build environments to add analysis information to your verification process. Like a compiler, CodeSonar does a build of your code using your existing build environment, but instead of creating object code, CodeSonar creates an abstract model of your entire program. From the derived model, CodeSonar’s symbolic execution engine explores program paths, reasoning about program variables and how they relate.
  • 2
    Veracode

    Veracode

    Veracode

    Veracode offers a holistic, scalable way to manage security risk across your entire application portfolio. We are the only solution that can provide visibility into application status across all testing types, including SAST, DAST, SCA, and manual penetration testing, in one centralized view.
  • 3
    Aevral

    Aevral

    Aevral

    Aevral is a GitHub security app built as an alternative to Claude Security. Two products, one install, neither requires the other. Whole-repo scans: deep at-rest scans of your repository for authorization, IDOR, and business-logic flaws. Every finding is a lead with evidence from your own code. Coverage verdicts are honest: an incomplete scan says so. You get a fix prompt for Claude Code, Cursor, or Codex. PR review: a reviewer on every pull request, opt-in per organization. A Check plus inline comments on the added lines, for authorization and business-logic flaws. Nothing merges without you.