
kit
Verified tool registry manager. Manages developer toolchains from git-based registries.

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Open-source, cross-platform, multi-purpose security auditing tool

A software supply chain framework powered by Nix.

A service that analyzes docker images and scans for vulnerabilities

Open-source pentesting management and automation platform by Salesforce Product Security

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

Collection of quality safety articles. Awesome articles.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

Secure, private AI agent operating system with local encrypted storage, OAuth/SSO authentication, policy-based access control, and extensible…

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

Enterprise-ready zero-trust access platform built on WireGuard®.

An open source threat modeling tool from OWASP

Community-driven knowledge base for pentesting cloud environments and CI/CD pipelines: attack techniques, enumeration, privilege escalation, and…

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

A reverse proxy like nginx, built on pingora, simple and efficient.

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.