
capslock
CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

Pluggable vulnerability assessment and management platform that orchestrates static and dynamic analysis scanners for web, mobile, network, and code,…

Agentless platform for discovering and managing VM security threats including vulnerabilities, malware, rootkits, misconfigurations, leaked secrets,…

Framework for automating security analysis pipelines by running a series of tools against filesystems, git repos, and other targets, with CI/CD…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Semantic static analysis engine and query library for detecting security vulnerabilities in source code, enabling automated code scanning and CI/CD…

CLI tool that filters npm package versions by minimum publication age to protect against supply chain attacks from recently compromised packages.

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Automated security audit wrapper for .NET binaries: runs CAT.NET static analysis on all .NET binaries in a folder and tracks findings in a database.

OWASP Static Application Security Testing (SAST) tool for analyzing code quality and vulnerabilities, designed for DevSecOps integration to help…

Source code security scanner for expert code review; emits file:line findings in plain text, designed for fast manual triage and filtering with…

Security-first wire protocol for agent coordination with mandatory mTLS, Ed25519-signed capability cards, Keycloak authentication, and per-call…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

The easiest, and most secure way to access and protect all of your infrastructure.

A reverse proxy like nginx, built on pingora, simple and efficient.

An active monitoring software to detect failures before your customers do.

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.