
renovate-operator
Operator to streamline renovate executions in Kubernetes

Operator to streamline renovate executions in Kubernetes

eBPF-based Security Observability and Runtime Enforcement

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Real-time, container-based file scanning at enterprise scale

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具


Open Source Cloud Native Application Protection Platform (CNAPP)

A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".


A terminal-based AWS Security Scanner with 102+ security checks across VPC, IAM, S3, CloudTrail, containers (ECS/EKS), and AI attack detection.…

A Docker-based research environment for analyzing CVE-2025-59532, a path traversal vulnerability in OpenAI Codex CLI that allows arbitrary file write…
