

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

GitHub Actions Pipeline Enumeration and Attack Tool

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

CVE-2024-38526 - Polyfill Scanner

Collect VEX documents and update VEX Hub

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Find log4j for CVE-2021-44228 on some places * Log4Shell

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.