
CVE-2026-32794
CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

Code signing and transparency for containers and binaries

Transparent file encryption in git

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

A modern git based age-encrypted secrets manager for teams.

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

Offline scanner for CVE-2026-29000 (CVSS 10.0) in org.pac4j:pac4j-jwt. Inspects jars/fat-jars directly, so it works where mvn dependency:tree cannot.…

A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord,…

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Security training for the apps you actually ship. Open your browser and start hacking.

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.