


The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

A collection of awesome resources related AI security

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Software Supply Chain Security Platform

Static analysis of malicious Python code

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

Source code for the Binaries of OWASP WrongSecrets

Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit…

Find, verify, and analyze leaked credentials

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

Backport of the CVE-2020-6950 security fix to Mojarra 2.2.13, providing a patched jsf-impl JAR with minimal, reviewable changes for legacy…

Open source vulnerability DB and triage service.

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d