
AI-SPM
This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

Source-built nginx 1.25.5 container with backported CVE-2026-42945 fix, OpenSSL bump, full provenance chain, and VEX attestation.

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Operator to streamline renovate executions in Kubernetes

Suppress vulnerabilities applying Kubernetes context to scans

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

AI runtime inventory: discover shadow AI, trace LLM calls

AI coding agents that can't exfiltrate secrets or merge their own PRs.

Find, verify, and analyze leaked credentials

The Most Comprehensive Docker Security Scanner

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Code signing and transparency for containers and binaries

Security scanner for AI agents, MCP servers and agent skills.