
python-tuf
Python reference implementation of The Update Framework (TUF)

Python reference implementation of The Update Framework (TUF)

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Pure-JS drop-in for [email protected] without the vulnerable native binding (CVE-2025-3194)

Offline and security-first tool for syncing and managing agent skills

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24

Patched Vue 2.7.16 template compiler with fixes for CVE‑2024‑6783 and CVE-2024-9506

RPM DB bindings for go

Patched google_gax 0.4.1 for Tesla 1.18.3+ compatibility (CVE-2026-48598)

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

Builds a SQLite database of Maven artifacts (ArtifactID, GroupID, Version, SHA1) for Trivy's Java component vulnerability detection, enabling scans…

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security…

A Python library to parse, validate and create SPDX documents.

Fork of lodash.template with CVE-2021-23337 fix (command injection via variable option)

Proof-of-concept exploit for CVE-2025-69604, demonstrating privilege escalation via malicious package installation in SuperDuper backup tasks on…

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Safely install NPM packages