
hijagger
Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Aggregates vulnerability data from multiple databases into CycloneDX SBOMs, generating deduplicated VEX, HTML, and GitLab-compatible reports for…

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Collect VEX documents and update VEX Hub