
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

A vulnerability scanner for container images and filesystems

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Scalable API key server for issuing, verifying, and revoking credentials with token derivation for fine-grained capability tokens. Supports…

CLI tool for the Horizon3.ai API

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

Ansible Playbook for CVE-2023-36845(Juniper Networks Junos OS 远程代码执行漏洞)

Invisible infrastructure for Dracon developer workspaces: git sync, system guard, and warden encryption utilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

A tool for secrets management, encryption as a service, and privileged access management

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Infisical is the open-source platform for secrets, certificates, and privileged access management.

⚙️ NGINX config generator on steroids 💉

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Simple and flexible tool for managing secrets

The easiest, and most secure way to access and protect all of your infrastructure.