
nixos-config
Lan Tian's NixOS Configuration

Lan Tian's NixOS Configuration

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Find, verify, and analyze leaked credentials

Pluggable linting tool to prevent committing credential.

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

Citrix NetScaler CVE Preconditions Checker as per CTX696604 | Supported CVE : CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816,…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

GitHub Action that scans ML model files for malicious code and security vulnerabilities

Scans Infrastructure as Code files for security misconfigurations and vulnerabilities using KICS, with Bitbucket Code Insights reporting.