
semgrep-rules
Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from…

Service that scans your Infrastructure as Code for common vulnerabilities

Suppress vulnerabilities applying Kubernetes context to scans

Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228

Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.

Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel…

Puppet Module to help fix and migrate a Puppet deployment (CVE-2011-3872)

Linux 内核升级指南 - 修复 CVE-2026-53359

Script - Workaround instructions to address CVE-2021-44228 in vCenter Server

OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner.

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to…

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

Ansible playbook for patching CVE-2024-3094


Linux 内核升级指南 - 修复 CVE-2026-64561

Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271