
airgap
Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Vulnerability Assessment Scanner with Report Generation

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

The Most Comprehensive Docker Security Scanner

Snyk CLI scans and monitors your projects for security vulnerabilities.

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

GitLab CI component for Trivy scanning


Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Vulnerable app with examples showing how to not use secrets

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

A Public Package Scanner for The Community