
core
OPNsense GUI, API and systems backend

OPNsense GUI, API and systems backend

Operator to streamline renovate executions in Kubernetes

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

This repository contains the scanner component for Greenbone Community Edition.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

GitHub App to set and enforce security policies

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

An open source threat modeling tool from OWASP

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Simple and flexible tool for managing secrets

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OpenSSF Scorecard - Security health metrics for Open Source

查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…