#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

RustSec API & Tooling

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

The Most Comprehensive Docker Security Scanner

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

GitHub App to set and enforce security policies


Open source solutions for SOC2, GDPR, and ISO27001

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages


Protect against malicious open source packages 🤖