
disclosure-check
Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Collect VEX documents and update VEX Hub

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

CVE-2024-38526 - Polyfill Scanner

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

Find log4j for CVE-2021-44228 on some places * Log4Shell

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.