
cve-2026-0300-audit
Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

This is a script designed for deployment on ubuntu instances patching the CVE-2026-3888 exploit

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271

Ansible playbook for patching CVE-2024-3094

Open Cloud Security Posture Management Engine

A software supply chain framework powered by Nix.

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

Write tests against structured configuration data using the Open Policy Agent Rego query language

Security risk analysis for Kubernetes resources

AWS Least Privilege for Distributed, High-Velocity Deployment

Getting a handle on container security

Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

DevSec SSH Baseline - InSpec Profile

Lan Tian's NixOS Configuration

DevSec Nginx Baseline - InSpec Profile