#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

python dependency vulnerability scanner, written in Rust.
Log4J CVE-2021-44228 : Mitigation Cheat Sheet

A macOS app to scan Xcode project files for possible security issues.

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

integration examples for the CVE-2020-25860 fix

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and…

Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk…

Vulnerability Scanner for Detecting Publicly Disclosed Vulnerabilities in Application Dependencies

Protection against Model Serialization Attacks

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…