
disclosure-check
Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

CLI tool that verifies Docker images for CVE-2018-8115 by checking layers for malicious files, helping ensure safe pulls from Docker Hub.

EU AI Act Compliance Tool - Risk classification and bias testing

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure