
kyverno
Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Community-owned database of security advisories for Python packages on PyPI, providing structured vulnerability data in OSV format for integration…

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and…

CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on…

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Proper sandboxing for agentic coding and web browsing

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

OpenSSF Scorecard - Security health metrics for Open Source

Operator to streamline renovate executions in Kubernetes

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…