
confused
Tool to check for dependency confusion vulnerabilities in multiple package management systems
supply-chain-securityvulnerability-analysis

Tool to check for dependency confusion vulnerabilities in multiple package management systems

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

A local package installation helper trusted caller-supplied package names too much. In yeoman-environment, missing generators could be installed…

Smart Tree: not just a tree, a philosophy. A context-aware, AI-crafted replacement for 20+ tools with MEM8 quantum compression, semantic search,…

PoC for CVE-2025-54416 tj-actions/branch-names command injection