
syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems

CLI tool and library for generating a Software Bill of Materials from container images and filesystems


A vulnerability scanner for container images and filesystems

A tool for secrets management, encryption as a service, and privileged access management

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

ProjectDiscovery's Open Source Tool Manager

CLI tool for inspecting and managing services listening on localhost ports

Static code analysis tool based on Elasticsearch

A terminal based tool for managing secrets with both tui and cli support

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Simple and flexible tool for managing secrets

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…