cherrybomb
« Back to VersTracker
Description:
Tool designed to validate your spec
Type: Formula  |  Tracked Since: Sep 16, 2024
Links: Homepage  |  GitHub  |  formulae.brew.sh
Stars: 1,231  |  Forks: 82  |  Language: Rust  |  Category: Security
Tags: api security openapi validation devsecops
Install: brew install cherrybomb
About:
Cherrybomb is a CLI tool that automatically validates OpenAPI (Swagger) specifications for security and correctness. It helps developers and security teams identify misconfigurations, vulnerabilities, and inconsistencies in API specs before deployment, reducing risk and improving API quality.
Key Features:
  • Automated OpenAPI/Swagger specification validation
  • Security vulnerability detection in API definitions
  • Detailed error reporting with severity levels
  • CLI-first design for easy integration into CI/CD pipelines
  • Supports multiple specification formats and versions
Use Cases:
  • Pre-production security scanning of API specifications
  • Integrating API spec validation into developer workflows and CI/CD
Alternatives:
  • openapi-generator – Primarily for code generation, includes basic validation but less focused on security auditing
  • spectral – General-purpose API style and quality linter, while Cherrybomb is more security-focused
Version History
Detected Version Rev Change Commit
Sep 16, 2024 10:48am 0 VERSION_BUMP 56ba67ee