
XcInspector
A macOS app to scan Xcode project files for possible security issues.

A macOS app to scan Xcode project files for possible security issues.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Offline Java tool that scans application jars to determine exposure to 14 Netty codec-http CVEs, identifying the exact patched version…

Offline Java tool that scans jars and versions to determine exposure to seven netty-codec-http2 CVEs, recommending the single patched version that…

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Scan and patch tool for CVE-2021-44228 and related log4j concerns.

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

A dead simple tool to sign files and verify digital signatures.

A Python library to parse, validate and create SPDX documents.

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

CVE-2026-43813: CloudAttestation enforceEnvironment bypass


🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Single-binary scanner for CVE-2021-44228 (Log4Shell) that detects vulnerable log4j versions in JAR/WAR/EAR files and applies mitigation patches by…