
sslyze
Fast and powerful SSL/TLS scanning library.

Fast and powerful SSL/TLS scanning library.

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Fast subdomain takeover scanner with 50+ signatures, supporting cloud provider integrations (AWS, Azure, Cloudflare) and CI/CD pipeline mode for…

Open-source dependency vulnerability scanner and supply chain security platform. Automatically detects CVEs in pull requests and builds, generates…

a guard that blocks catastrophic agent actions

Integration of Clair and Docker Registry

Static analyzer for NGINX configurations that detects security misconfigurations, hardening gaps, and performance issues before production deployment.

A simple file-based scanner to look for potential AWS access and secret keys in files

Terminal-based security auditor that statically analyzes shell scripts and commands, dynamically enforces sandboxing via Linux Landlock, and provides…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Public OCI-Image (docker image) Security Checker

Defense Against the Shai-Hulud Supply Chain Attack

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Detects and mitigates CVE-2025-30749 RCE vulnerability in Oracle Java SE by scanning installed versions and flagging unpatched installations for…

Detects and fixes CVE-2025-55182 (React2Shell) in React Server Components and Next.js apps. Scans package versions, suggests safe upgrades, and…