
vuln-list-update
Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Open source vulnerability DB and triage service.

Malicious package & supply-chain intelligence

VEX Repository Specification

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Open source solutions for SOC2, GDPR, and ISO27001

Accompanying PowerShell Modules for DevSec Defense Presentation

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

CLI scanner that detects likely vulnerable React/Next.js dependencies for CVE-2025-55182 and provides mitigation targets. Supports JSON output and…

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

Protection against Model Serialization Attacks

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Purple Team Exercise Framework