
ftw
YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Static code analysis plugin for Android project. (Checkstyle, PMD)

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

OWASP project defining an AI Bill of Materials (AIBOM) standard to document AI/ML components, dependencies, and supply chain risks for AI security…

Generates CycloneDX SBOMs and dependency scanning reports to identify project dependencies, licenses, and vulnerabilities within GitLab CI/CD…

Authorized security-research lab reproducing CVE-2026-31852 (jellyfin/jellyfin-ios pull_request_target pwn in code-quality.yml) — isolated snapshot,…

A macOS app to scan Xcode project files for possible security issues.

Sample project that uses VEX to supress CVE-2024-29415.

Software composition analysis tool that detects publicly disclosed vulnerabilities in project dependencies using CPE matching, generating detailed…

A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

Project Aura: Security auditing and code introspection

A project security/vulnerability/risk scanning tool

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…