
in-toto
Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

Open standard for documenting security-relevant metadata of AI models, including training data provenance, PII risk, known vulnerabilities, and…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

go CVE-2023-24538 patch issue resolver - Kirkstone

a scenario based on CVE-2022-25845 yielding a TP for metadata based SCA but a FN if the callgraph is used

A local package installation helper trusted caller-supplied package names too much. In yeoman-environment, missing generators could be installed…

go CVE-2023-24538 patch issue resolver - Dunfell

VEX Repository Specification

Proof-of-concept demonstrating a path traversal vulnerability (CVE-2026-35204) in Helm plugin installation, allowing arbitrary file write via crafted…