
octoscan
Octoscan is a static vulnerability scanner for GitHub action workflows.

Octoscan is a static vulnerability scanner for GitHub action workflows.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker



CVE-2026-43813: CloudAttestation enforceEnvironment bypass

RPM DB bindings for go

Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

RustSec API & Tooling

Code signing and transparency for containers and binaries

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.