
guarddog
🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Tool to check for dependency confusion vulnerabilities in multiple package management systems

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

CLI tool to scan codebases for quantum-vulnerable cryptography

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects


Public OCI-Image (docker image) Security Checker

Defense Against the Shai-Hulud Supply Chain Attack

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

A GitHub Action to find Unicode control characters using the Red Hat diagnostic tool https://access.redhat.com/security/vulnerabilities/RHSB-2021-007…

A specialized vulnerability scanner designed to detect CVE-2024-38526, the Polyfill.io Supply Chain Attack, helping organizations identify and…

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Static analysis of malicious Python code