
jackson-check
jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512

jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512


Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…


Apache RAT (Release Audit Tool) Gradle Plugin

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages



One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

A GitHub Action to find Unicode control characters using the Red Hat diagnostic tool https://access.redhat.com/security/vulnerabilities/RHSB-2021-007…


Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security…


Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Apache's commons-lang2 v2.6 with a backported fix for CVE-2025-48924

Defense Against the Shai-Hulud Supply Chain Attack