
chain-bench
Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

a guard that blocks catastrophic agent actions

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

Integration of Clair and Docker Registry

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

Rust-powered HTTP Request Smuggling Scanner.

A simple file-based scanner to look for potential AWS access and secret keys in files

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Public OCI-Image (docker image) Security Checker

Defense Against the Shai-Hulud Supply Chain Attack

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…