
TrojanSourceFinder
🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs,…

A documentation and tracking project with the goal of making package management systems more secure.

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

A Git-native dependency admission controller. Evaluates trust signals on every dependency change and blocks commits or builds when packages fail your…

RCE in NPM VSCode Extension

🐺 Vulfy – Fast Rust based package version scanner

Exploit for CVE-2024-0402 in Gitlab

Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

Apache RAT (Release Audit Tool) Gradle Plugin