#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Getting a handle on container security

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

File-system scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046) by analyzing compiled Java classes, including nested…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Minimal CVE Hardened container image collection

Operator to streamline renovate executions in Kubernetes

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

Protection against Model Serialization Attacks

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

Microsoft's curated repository of secure boot objects (KeK, Db, Dbx) for firmware and runtime, enabling transparent revocation updates and…

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets