
sbomlyze
Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Passive recon & attack surface mapper — zero requests sent

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

This is a mirror of a forked repository. It adds several features to gitrob including GitLab support, commit content searching, in-memory repository…

NER-based document scanner that detects sensitive data (PII, financial info, IDs) in files and assigns a sensitivity score. Supports bulk analysis…

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Identify hardcoded secrets in static structured text

a Go code to detect leaks in JS files via regex patterns

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Open-source platform for secrets, certificates, and privileged access management with secret scanning, dynamic secrets, PKI, and CI/CD integrations.…

Transparent file encryption in git

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

CyberArk Conjur automatically secures secrets used by privileged users and machine identities

Local-first password manager with direct device-to-device sync