Three labels, three rules
AppSec Santa uses three related inclusion labels. A tool can qualify for more than one.
Open-source X tools (e.g. /open-source-sca-tools) — the core scanner is licensed under an OSI-approved licence
, runs locally without a vendor account, and its source repository is public.
Free X tools (e.g. /free-dast-tools) — a meaningful free tier or community edition exists with publicly documented limits. Not a 14-day trial, not a request-access gate.
Category pages (e.g. /sca-tools) — an active product or project fits the security category, and current official documentation or a public repository supports the listing. Category pages can include open-source, free, freemium, and commercial tools. Inclusion is a baseline, not a recommendation.
Examples
| Tool | Open-source list | Free list | Category page |
|---|---|---|---|
| Trivy | ✓ | ✓ | ✓ |
| Snyk Open Source | — | ✓ | ✓ |
| Checkmarx One | — | — | ✓ |
How to submit a tool
Use the contact form and include the tool name, the list URL you’re asking to appear on, and a link I can verify the claim from (licence file, pricing page, public repo).
Submission is free. I review submissions against the published criteria and may ask for clearer evidence before making a decision.
Disagreements
If you think a tool was wrongly included or excluded, email suphi@cnt.fi with the criterion and the evidence. I prioritize factual corrections. Placement and ordering remain editorial decisions.