
sast-rules
Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A collection of my Semgrep rules to facilitate vulnerability research.

Clickbait. The CVE is AI slop.

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

CVE-2026-39259

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

The Secure Coding Practices Quick-reference Guide from OWASP

A collection of smart contract vulnerabilities along with prevention methods

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

Type-safe Java Mustache templating engine with compile-time template validation, static value binding, and extensible escaping for HTML and other…

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.