
kyverno
Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Software Supply Chain Security Platform

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Security training for the apps you actually ship. Open your browser and start hacking.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Open source solutions for SOC2, GDPR, and ISO27001

Source code for the Binaries of OWASP WrongSecrets

Plugin for integrating Trivy with Aqua Security platform to scan IaC, pipelines, and dependencies for vulnerabilities and misconfigurations.

CS50 Cybersecurity Final Project - Analysis of CVE-2024-3094

Local proof-of-concept for CVE-2026-71557 demonstrating path traversal in go-git filesystem reference storage, including exploit logic and…

Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack

Demonstrates how a malicious Python package executes arbitrary commands during pip install via setup.py, highlighting PyPI supply chain and…

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

Path traversal (Tar Slip) in Cornac via _extract_archive (CVE-2026-43637)

Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

Aurea is an open-source, AI-powered platform that secures infrastructure-as-code (IaC) across Terraform, Kubernetes, Docker, and Ansible. It…

Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.