
cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Source code for the Binaries of OWASP WrongSecrets

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.


OWASP Smart Contract Security (SCS) Project

OWASP Certified Secure-Software Developer

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…
