secguide
by Tencent
A comprehensive secure coding guide for developers that outlines API-level risks and provides practical security coding solutions.
面向开发人员梳理的代码安全指南
Primary Use Case
This tool serves as a detailed reference for developers to understand and mitigate security risks in their code by following language-specific secure coding guidelines. It is useful for developers, security engineers, and DevSecOps teams aiming to integrate security best practices into development workflows and to create or enhance security scanning and vulnerability remediation strategies.
- Detailed secure coding guidelines for multiple programming languages including C/C++, JavaScript, Node.js, Go, Java, and Python
- Focus on API-level security risks and practical coding solutions
- Based on DevSecOps principles to promote security from the development source
- Guidance for writing security system scanning strategies
- Support for security component development and vulnerability fixing
- Community-driven with contribution guidelines
- Licensed under CC BY 4.0 for open collaboration
- Integrate the secure coding guidelines into CI/CD pipelines to automate vulnerability prevention early in development.
- Use the documentation to train developers and DevSecOps teams, reducing introduction of exploitable code.
- Leverage the guide to customize and enhance static and dynamic application security testing tools for improved scanning accuracy.
- Combine with runtime application self-protection (RASP) tools to create a layered defense from code to runtime.
- Encourage community contributions to keep the guide updated with emerging language-specific security risks and mitigation techniques.
Docs Take 2 Hours. AI Takes 10 Seconds.
Ask anything about secguide. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.
3 free chats per tool • Instant responses • No credit card
Related Tools
PayloadsAllTheThings
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

hoppscotch
hoppscotch/hoppscotch
Open source API development ecosystem - https://hoppscotch.io (open-source alternative to Postman, Insomnia)
ImHex
WerWolv/ImHex
🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

termux-app
termux/termux-app
Termux - a terminal emulator application for Android OS extendible by variety of packages.

sentry
getsentry/sentry
Developer-first error tracking and performance monitoring
CheatSheetSeries
OWASP/CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
