
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable pip app (PyYAML CVE-2020-14343) remediated to sealed versions; GitHub Actions + Jenkins integration

ClusterImagePolicy demo for cve-2022-42889 text4shell

EU focused compliance MCP server

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.