
hardware-compliance-handbook
AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and…

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and…

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

Protection against Model Serialization Attacks

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

A dead simple tool to sign files and verify digital signatures.

A Python library to parse, validate and create SPDX documents.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Cryptographic and general-purpose routines for Secure Systems Lab projects at NYU

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…


Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Structured security knowledge base with production-inspired cases: vulnerability analysis, exploit explanation, remediation, and DevSecOps for…

The credit score for npm packages. Analyze package reputation, maintenance, security, publisher trust, and ecosystem health before you install any…

Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.