
jsonorg-tp1
simple application with a CVE-2022-45688 vulnerability

simple application with a CVE-2022-45688 vulnerability
Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.

Source code for the Binaries of OWASP WrongSecrets

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

Technical analysis and writeup of CVE-2024-3094, the XZ Utils backdoor. Explores the supply-chain attack, exploitation mechanics, and detection…

Demonstration script simulating a supply chain attack through GitHub releases, highlighting the risk of malicious code in release artifacts.

A documentation and tracking project with the goal of making package management systems more secure.

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

general purpose workaround for the log4j CVE-2021-44228 vulnerability

Batch upgrade all your Next.js apps to patched versions - fight back against CVE-2025-55183/55184/67779

Monitors cryptographic integrity of container images, releases, and Git tags for supply chain security, verifying Sigstore cosign signatures with…

Snyk CLI scans and monitors your projects for security vulnerabilities.

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Ansible playbook for patching CVE-2024-3094

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.