
o1js-scan
Dependency-free static analyzer for zk circuit soundness bugs in o1js/Mina zkApps and Noir circuits

Dependency-free static analyzer for zk circuit soundness bugs in o1js/Mina zkApps and Noir circuits

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

.NET 7 fork of seal-security-nuget-demo: same CVE-2024-21907 exploit story, retargeted for customers locked to .NET SDK 7.

Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

System utility that identifies and restarts daemons using outdated libraries after package upgrades to maintain security. Supports containers and…

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

Jenkins plugin providing shared API for Docker credential management, registry authentication, daemon configuration, and image fingerprinting across…

CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

eBPF-powered Linux observability with AI incident detection. AGPL-3.0 licensed.

OPA Gatekeeper-based policy templates to mitigate CVE-2020-8554 by restricting Kubernetes Service external IPs to an allow list, preventing traffic…

Sample project that uses VEX to supress CVE-2024-29415.

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Suppress vulnerabilities applying Kubernetes context to scans