
raptor
Web-based Source Code Vulnerability Scanner

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

OWASP Security Culture repository

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

CVE-2025-53652: Jenkins Git Parameter Analysis

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

Security toolkit to detect CVE-2025-55182 (React2Shell) vulnerability

A lightweight, recursive Bash script to detect Next.js and React Server DOM versions vulnerable to CVE-2025-55182 (React2Shell) in local projects.

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…

The dependency-check repository has moved: