
ff4j__ff4j_CVE-2022-44262_1_8_13_fixed
Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Open source integration framework for defining routing and mediation rules via DSLs (Java, XML, YAML) to connect various systems consuming or…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Read-only scanner for git settings that let a repository run code in coding agents (Claude Code, Codex, Cursor, Copilot). Covers the GitSpawn class…

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

Project Aura: Security auditing and code introspection


Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…


Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize


OpenSSF Scorecard - Security health metrics for Open Source

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.