
static-analysis
Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Centralized configuration server for distributed systems with HTTP API, encryption/decryption of properties, and support for Git, Vault, JDBC, and…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

The easiest, and most secure way to access and protect all of your infrastructure.

DSC resources to simplify administration of certificates on a Windows Server.

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see…

Scans GitHub workflows and logs for indicators of CVE-2025-30066, detecting malicious actions and exposed secrets using Checkmarx 2ms integration.

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Proof-of-concept for CVE-2021-31166 (http.sys RCE) with Terraform deployment on AWS, including testing scripts and a WAFv2 rule to block the exploit.

Community-owned database of security advisories for Python packages on PyPI, providing structured vulnerability data in OSV format for integration…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…