
VulnReach
Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Defense Against the Shai-Hulud Supply Chain Attack

Sean's Surf & Skate Co. — Spring Boot storefront with a vulnerable SnakeYAML dep (CVE-2022-1471) for Seal Security demos

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).




PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545


Project Aura: Security auditing and code introspection

Anteater - CI/CD Gate Check Framework

The dependency-check repository has moved:

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize