Security and supply chain — linters for the rules that bind software
Rules that now reach the code itself: the EU Cyber Resilience Act, SBOM and advisory formats, PCI DSS script controls and shorter certificate lifetimes. The linters run in your editor or CI and never upload your repository.
27 tools
Oracle JDK License Gate
VS Code extension
Finds the Java lines in your build that Oracle now bills for, and the free line that replaces each one
VS Code Marketplace: 47 installs
Firmware Release Gate for sdkconfig and prj.conf
VS Code extension
Finds the build-config lines that ship an ESP-IDF or Zephyr device with secure boot off, a debug port open, unsigned images or plaintext OTA.
SBOM Field Check for CRA 2026
VS Code extension
Names every missing field in your CycloneDX or SPDX SBOM against BSI TR-03183-2 and the CISA 2026 minimum elements. 34 rules. Runs offline.
TLS Cert Lifetime Lint - SC-081v3 renewal check
VS Code extension
Finds the 12 settings that break when public TLS certificates fall to 100 days on 2027-03-15: openssl -days, Terraform, cert-manager, late expiry alerts, HPKP, TLS…
AI Model License Lint
VS Code extension
Reads the open-weight model IDs in your code and names the licence clause that binds you - 22 rules, 17 findings on a 33-line fixture
Firestore Rules Guard
VS Code extension
Audits firestore.rules and storage.rules for public access, expired test-mode dates and missing owner checks — 13 rules, line by line, before you deploy.
SQL Card Data Lint (PCI DSS Req 3)
VS Code extension
Names every column, index, view and seed row in a .sql migration that stores card data, with its PCI DSS Requirement 3 rule id
License Flip Audit - BUSL/SSPL/AGPL in your deps
VS Code extension
Finds the dependencies whose licence changed under you - Terraform 1.6+ BUSL, Redis 7.4+ SSPL, Bitnami's August 2025 move, Elastic 7.11 - and names the exact version…
PCI Payment Page Script Audit: requirement 6.4.3 and 11.6.1 on your checkout markup
VS Code extension
PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 have been mandatory since 2025-03-31, and the PCI SSC revised FAQ 1331 on 2026-08-04 so a QSA agreement alone no longer marks…
Crypto Export Notice Lint (EAR 742.15)
VS Code extension
Ten checks on the export paragraph of a repository that ships encryption
Cybersecurity Container Audit — NIST SP 800-190
VS Code extension
Reads a Dockerfile or compose file and names the hardening controls it fails, with the NIST SP 800-171 requirement each one puts at risk.
Webfont License Audit
VS Code extension
The 12 licence questions a foundry audit letter asks, run against your CSS
RED Cybersecurity DoC Lint (EN 18031)
VS Code extension
Checks an EU declaration of conformity for radio equipment against Delegated Regulation (EU) 2022/30 and the EN 18031:2024 citations
CRA Annex II User Docs Lint
VS Code extension
19 rules over the user documentation that ships with your product: support-period end date, vulnerability reporting contact, EU declaration of conformity address, secure…
Terraform State Secret Leak Lint
VS Code extension
Names the attributes, outputs and backends that copy a cleartext secret into terraform.tfstate
1099-DA Basis Gap Checker (2026)
Browser extension · Chrome, Edge, Firefox
See which of your 2026 crypto sales reach the IRS with box 1e blank - and price what that blank costs.
SPF & DMARC Record Lint
VS Code extension
19 offline checks on the SPF, DMARC and DKIM records in your branch — including the DMARC rewrite of May 2026
.NET EOL & CRA Support Window Gate
VS Code extension
Dates every target framework in a .csproj against Microsoft's end-of-support day and against the support period you promise
OpenAPI Security Contract Lint
VS Code extension
Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in the query string, or an OAuth grant RFC 9700 forbids.
security.txt Lint - RFC 9116 + CRA contact point
VS Code extension
13 rules that decide whether a vulnerability report ever reaches you
CRA 24/72/14 Reporting Lint (Article 14)
VS Code extension
Reads your SECURITY.md against the EU Cyber Resilience Act reporting clock that started on 11 September 2026 — 24 hours, 72 hours, 14 days, to ENISA and your…
CSAF Advisory Check for CRA 2026
VS Code extension
Runs all 43 mandatory and profile conformance tests of CSAF 2.0 section 6.1 on the advisory you are writing: product ID graph, revision history, CVSS recomputed from the…
SPDX License Field Lint for package.json, pyproject.toml and Cargo.toml
VS Code extension
Reads the licence field in the open manifest and names every deprecated SPDX id, invalid string, PEP 639 leftover and copyleft obligation - with the exact replacement…
CRA Readiness Audit for EU Cyber Resilience Act
VS Code extension
Flags the lines in your repo that break the EU Cyber Resilience Act - default passwords, disabled TLS checks, floating base images, an expired security.txt - naming the…
Security Headers Lint - CSP and Dead Headers
VS Code extension
Reads security headers and CSP line by line in your config file and names the lines that silently do nothing: retired headers, keywords missing their quotes, directives…
Connection String & Secret Audit — 8 Stacks
VS Code extension
26 rules and 32 safe-replacement snippets for hardcoded connection strings, keys and kubeconfigs across 8 VS Code stacks. Runs on your machine and sends nothing anywhere.
Hugging Face Model Licence Matrix — all 70 model-card `license:` identifiers × the 4 questions a commercial release turns on
Copy the `license:` string off the model card, read four rows, close the review ticket — 70 identifiers, 4 questions, 280 rows, every row naming the clause it came from.
Questions
Do my files leave my computer?
No. The extensions and command-line checks run on your machine and your files are not uploaded. The browser calculators run in the page.
What does it cost?
Every tool is free for the file or case in front of you. The paid part is a one-time licence key; each tool page shows its price and what the key adds. A team key ($149 once) opens every ReadyStack linter for five seats and CI.
More collections
US payroll, tax and filing deadlines — 2026 checksUK tax, payroll and HMRC rules — 2026/27 checksEU rules with a 2026 date — deadline and fine checksE-invoicing rules — format and deadline checksPrivacy and data protection — rule checksAccessibility — WCAG and EAA checksDeveloper deadlines — deprecations, removed APIs and build breaksSelling online — pricing, fee, email and consumer-law rulesAI rules and agent configuration — lintersSubmission gates — pass the store or registry review the first timeHealth and medical software — regulatory checksTemplates and design assetsDeutschland 2026 – Fristen, Lohn, Steuer und Pflichten2026年の申告・インボイス・社会保険 チェッカーとテンプレート All tools