
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Tool to check for dependency confusion vulnerabilities in multiple package management systems

A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical…

Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…

Modular Node.js runtime orchestrator with HMAC integrity verification, import guards, and sandboxed execution for secure, layered application…

eBPF-powered runtime security sensor for CI/CD pipelines. Detects supply-chain attacks, logs process ancestry and file access, and provides forensic…

GitLab CI component for Trivy scanning

Tamper-evident runtime evidence for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.

GitHub Action for Heisenberg SSC

Security scanner for AI agents, MCP servers and agent skills.

A vulnerability scanner for container images and filesystems

patches for SNYK-JS-JQUERY-565129, SNYK-JS-JQUERY-567880, CVE-2020-1102, CVE-2020-11023, includes the patches for SNYK-JS-JQUERY-174006,…

patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428

Sample project to test using Microsoft.CodeDom.Providers.DotNetCompilerPlatform 2.0.1 causing CVE-2017-0248

integration examples for the CVE-2020-25860 fix

apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links

Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574