
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Proof of concept for CVE-2024-24590

agent runtime security - zero trust, zero setup, zero latency.

A macOS app to scan Xcode project files for possible security issues.

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Curated repository of Qubes OS security bulletins, canaries, PGP keys, and ISO digests, with authenticated verification via git tags and detached…

Project Aura: Security auditing and code introspection

Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

Authorized security-research lab reproducing CVE-2026-45131 (pwn request in .github/workflows/pull-request.yaml) — snapshot of…

A documentation and tracking project with the goal of making package management systems more secure.

general purpose workaround for the log4j CVE-2021-44228 vulnerability

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector