

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

GitHub Actions Pipeline Enumeration and Attack Tool

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation