
bromure
Proper sandboxing for agentic coding and web browsing

Proper sandboxing for agentic coding and web browsing

Signing-key abuse and update exploitation framework

GNU IFUNC is the real culprit behind CVE-2024-3094


Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk…

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.

Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

Scan and patch tool for CVE-2021-44228 and related log4j concerns.

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

An agent to hotpatch the log4j RCE from CVE-2021-44228.