
SBOM-VEX-Taint-Analysis
Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.


The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP Thick Client Application Security Verification Standard

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Software Component Verification Standard (SCVS)

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC


AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

An open, vendor-neutral verification standard for traceable, reviewable, and rights-aware open-source intelligence. Current release: OOVS v0.1.0.