
wrongsecrets-binaries
Source code for the Binaries of OWASP WrongSecrets

Source code for the Binaries of OWASP WrongSecrets

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

The dependency-check repository has moved:

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Software Component Verification Standard (SCVS)

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

OWASP Autonomous Penetration Testing Standard

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.