
zttp
Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

One security-remediation.sh for CVE-2026-41940 (cPanel), CVE-2026-31431 (kernel "Copy Fail"), CSF, optional domain/proxy cleanup, and optional…

integration examples for the CVE-2020-25860 fix

This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.

Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in…

Provides a security patch for CVE-2026-0915, adding strict JSON schema validation, input sanitization, and rate limiting to prevent injection and DoS…

CVE-2025-55752 CVE-2025-55754 CVE-2025-48988 CVE-2025-52520 CVE-2025-53506 CVE-2025-61795 CVE-2025-66614:Tomcat 8.5 已 EOL,终版 8.5.100。Apache 逐条声明「8.5…

OpenRewrite recipe that detects and fixes Spring Security header suppression (CVE-2026-22732) by identifying Content-Length header misuse and…

Mitigates CVE-2016-5195 aka DirtyCOW

Patch for CVE-2014-6271

cookbook for update glibc. CVE-2015-0235(GHOST)

kube-scan: Octarine k8s cluster risk assessment tool

The dependency-check repository has moved:

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks


AI coding agents that can't exfiltrate secrets or merge their own PRs.

Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898