
DockSec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP Kubernetes security and compliance tool [WIP]

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

OWASP Domain Protect - prevent subdomain takeover

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…


Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.