
Astra
Automated Security Testing For REST API's

Automated Security Testing For REST API's

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

The DevSecOps toolset for REST APIs

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

OWASP project defining an AI Bill of Materials (AIBOM) standard to document AI/ML components, dependencies, and supply chain risks for AI security…

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

OWASP Security Culture repository

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Getting a handle on container security