Detekt security rules for Spring Boot: missing @PreAuthorize, CSRF disabled, permissive CORS, SpEL injection, Thymeleaf SSTI, insecure actuator exposure, hardcoded datasource passwords, weak BCrypt rounds, JWT issues, and 45+ more rules.
Artifacts using Kotlin Security Scanner — Spring Boot (1)
Detekt security plugin covering OWASP Top 10 for Kotlin/JVM — 200+ rules across Spring Boot, Quarkus, Dropwizard, Ktor, Micronaut, and Vert.x. Catches SQL injection, weak crypto, hardcoded secrets, insecure config, and more at compile time in CI.
Last Release on Jun 30, 2026
- Prev
- 1
- Next