If you're looking for a GitGuardian alternative, Bearer is another good option. It's deeply integrated with CI/CD pipelines and can spot sensitive data like PII and PHI. It has customizable rules and reporting, too, so it's designed to be useful to developers using SAST. Bearer supports many programming languages and integrates with Jira and Slack.
Another option is Snyk, which is designed to work within your development tools and processes to find, prioritize and fix security vulnerabilities. It offers continuous vulnerability scanning and remediation advice, so it's a full security service. Snyk supports a broad range of languages and tools, including Docker, Kubernetes and CI/CD pipelines.
If you want real-time security context, check out DryRun Security. It works as a GitHub App and uses AI-powered Security Buddy for fast and accurate code reviews. It evaluates authentication, authorization and sensitive code paths to help developers work more efficiently and speed up the development pipeline. DryRun Security supports multiple languages and frameworks.
Last, Sonar is a mature service designed to ensure your code is high quality and secure. It can analyze code right in your IDE and in cloud-based continuous integration and delivery workflows. Sonar integrates with many development tools, including GitHub and GitLab, and is designed to keep code clean and at a high level of quality so developers can focus on innovation.