
fulcio
Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

Code signing and transparency for containers and binaries

A modern git based age-encrypted secrets manager for teams.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Agent Control Protocol (ACP) — Official English specification. Cryptographically verifiable authorization architecture for autonomous AI agents.

Demonstrates CVE-2026-1122 Ed25519 signature bypass via low-order point injection, forging malicious IoT firmware updates with Python and C verifier…

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

GNU IFUNC is the real culprit behind CVE-2024-3094

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

PoC: CVE-2025-30065 incomplete fix bypass in Apache Parquet Java 1.15.1