
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Protect against malicious open source packages 🤖

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

The code for personally reproducing the corresponding vulnerability


Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs,…

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Docker Deskop giving issue CVE-2024-26308 for maven [reproduce]