Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Getting Started - FAQ - Documentation - Report a Bug
[![GitHub Release][release-img]][release]
[![Test][test-img]][test]
Bearer CLI (Open Source): Go • Java • JavaScript • TypeScript • PHP • Python • Ruby
Bearer Pro by Cycode: All Bearer CLI languages plus:
Learn more about language support
https://user-images.githubusercontent.com/1649672/230438696-9bb0fd35-2aa9-4273-9970-733189d01ff1.mp4
Bearer CLI scans your source code for:
Security risks and vulnerabilities using built-in rules covering the OWASP Top 10 and CWE Top 25, such as:
Note: all the rules and their code patterns are accessible through the documentation.
Privacy risks with the ability to detect sensitive data flow such as the use of PII, PHI in your app, and components processing sensitive data (e.g. databases like pgSQL, third-party APIs such as OpenAI, Sentry, etc.). This helps generate a privacy report relevant for:
Discover your most critical security risks and vulnerabilities in only a few minutes. In this guide, you will install Bearer CLI, run a security scan on a local project, and view the results. Let's get started!
The quickest way to install Bearer CLI is with the install script. It will auto-select the best build for your architecture. Defaults installation to ./bin and to the latest release version:
curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh
Using Bearer CLI's official Homebrew tap:
brew install bearer/tap/bearer
Update an existing installation with the following:
brew update && brew upgrade bearer/tap/bearer
sudo apt-get update && sudo apt-get install ca-certificates -y && sudo update-ca-certificates
sudo apt-get install apt-transport-https
echo -e "Types: deb\nURIs: https://apt.fury.io/bearer/\nSuites: /\nTrusted: yes" | sudo tee /etc/apt/sources.list.d/fury.sources
sudo apt-get update
sudo apt-get install bearer
Update an existing installation with the following:
sudo apt-get update
sudo apt-get install bearer
Add repository setting:
$ sudo vim /etc/yum.repos.d/fury.repo
[fury]
name=Gemfury Private Repo
baseurl=https://yum.fury.io/bearer/
enabled=1
gpgcheck=0
Then install with yum:
sudo yum -y update
sudo yum -y install bearer
Update an existing installation with the following:
sudo yum -y update bearer
Bearer CLI is also available as a Docker image on Docker Hub and ghcr.io.
With docker installed, you can run the following command with the appropriate paths in place of the examples.
docker run --rm -v /path/to/repo:/tmp/scan bearer/bearer:latest-amd64 scan /tmp/scan
Additionally, you can use docker compose. Add the following to your docker-compose.yml file and replace the volumes with the appropriate paths for your project:
version: "3"
services:
bearer:
platform: linux/amd64
image: bearer/bearer:latest-amd64
volumes:
- /path/to/repo:/tmp/scan
Then, run the docker compose run command to run Bearer CLI with any specified flags:
docker compose run bearer scan /tmp/scan --debug
The Docker configurations above will always use the latest release.
Download the archive file for your operating system/architecture from here.
Unpack the archive, and put the binary somewhere in your $PATH (on UNIX-y systems, /usr/local/bin or the like). Make sure it has permission to execute.
To update Bearer CLI when using the binary, download the latest release and overwrite your existing installation location.
The easiest way to try out Bearer CLI is with the OWASP Juice Shop example project. It simulates a realistic JavaScript application with common security flaws. Clone or download it to a convenient location to get started.
git clone https://github.com/juice-shop/juice-shop.git
Now, run the scan command with bearer scan on the project directory:
bearer scan juice-shop
A progress bar will display the status of the scan.
Once the scan is complete, Bearer CLI will output, by default, a security report with details of any rule findings, as well as where in the codebase the infractions happened and why.