
osv.dev
Open source vulnerability DB and triage service.

Open source vulnerability DB and triage service.

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.


Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701

apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Agent-Isolated Credential Broker for AI Agents

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

AURORA demo target — deliberately vulnerable lockfiles (CVE-2019-10744, CVE-2018-18074, CVE-2020-26160)
