
aquaman
🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

A vulnerability scanner for container images and filesystems

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Transparent file encryption in git

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Code signing and transparency for containers and binaries

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

Tool to check for dependency confusion vulnerabilities in multiple package management systems

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…