
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

Minimal CVE Hardened container image collection

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

TPM Genie is an I2C bus interposer for discrete Trusted Platform Modules

An agent to hotpatch the log4j RCE from CVE-2021-44228.

Harden your package manager configs against supply chain attacks.

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Demonstration of CVE-2017-1000117: a Git vulnerability triggered by recursive cloning of malicious submodules, causing arbitrary command execution.