
dependency-track
Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Autonomous Penetration Testing Standard

Getting a handle on container security

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Software Component Verification Standard (SCVS)

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

The dependency-check repository has moved:

A documentation and tracking project with the goal of making package management systems more secure.

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis