
flar
Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

Go-based automation tool that scans GitHub repositories for vulnerable Next.js versions (CVE-2025-66478) and automatically creates pull requests with…

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

A dead simple tool to sign files and verify digital signatures.

Defense Against the Shai-Hulud Supply Chain Attack

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Identify hardcoded secrets in static structured text

GitHub Actions Pipeline Enumeration and Attack Tool

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

CVE-2018-6574 this vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system by installing a malicious…

This is the exploit of CVE-2018-6574: go get RCE

Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…