
disclosure-check
Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

CLI tool that verifies Docker images for CVE-2018-8115 by checking layers for malicious files, helping ensure safe pulls from Docker Hub.

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…

Open source vulnerability DB and triage service.

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…