

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Getting a handle on container security

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Source code for the Binaries of OWASP WrongSecrets


A documentation and tracking project with the goal of making package management systems more secure.

SecureML - Securing and Watermarking AL models

Software Component Verification Standard (SCVS)


Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis