
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

Kubernetes DaemonSet that hot-patches JVMs to mitigate Log4j2 vulnerabilities (CVE-2021-44228, CVE-2021-45046) by disabling JNDI lookups, providing…

Executable security regression testing for agentic applications and MCP-integrated systems.

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

DSC resources to simplify administration of certificates on a Windows Server.

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Static code analysis plugin for Android project. (Checkstyle, PMD)

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

OWASP project defining an AI Bill of Materials (AIBOM) standard to document AI/ML components, dependencies, and supply chain risks for AI security…