
DevSecOpsGuideline
The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Community-driven framework defining activities, controls, and best practices to identify and reduce risk in software supply chains, with incremental…

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

OWASP Autonomous Penetration Testing Standard

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

Multi-language binary compilation and CTF generation for OWASP WrongSecrets, with automated security scanning (CodeQL, Semgrep) for secrets detection…

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

Hands-on lab for the OWASP Top 10 for LLM Applications (2025) with rule-based challenges, payload editor, and progressive hints. No real LLM required.

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

OWASP-curated guide to the top 10 proactive security controls for Docker and containerized environments, covering threat modeling, configuration…

Community-driven catalog of testable security requirements for AI-enabled systems. Provides a structured checklist for developers and security…