
flar
Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

Go-based automation tool that scans GitHub repositories for vulnerable Next.js versions (CVE-2025-66478) and automatically creates pull requests with…

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

AWS Testing and Reporting Management Tool

Integration of Clair and Docker Registry

Defense Against the Shai-Hulud Supply Chain Attack

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

ProjectDiscovery's Open Source Tool Manager

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

The easiest, and most secure way to access and protect all of your infrastructure.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives