
Creosote
Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

Open source compliance tool for development platforms.

A static analysis tool for securing Go code

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)

Provides a quick workaround for the segfault bug in Ruby (CVE-2009-1904)

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402