
AuraBorealisApp
Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.



Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Defense Against the Shai-Hulud Supply Chain Attack

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Static analysis of malicious Python code

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Open source compliance tool for development platforms.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.