
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

A Python pickling decompiler and static analyzer

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Proof of concept for CVE-2024-24590

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

python dependency vulnerability scanner, written in Rust.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Security scanner for AI agents, MCP servers and agent skills.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.