
supply-chain-monitor
Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…


Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

The Most Comprehensive Docker Security Scanner


Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Batch upgrade all your Next.js apps to patched versions - fight back against CVE-2025-55183/55184/67779

GitHub Action for Heisenberg SSC

Cargo exploit from CVE-2023-38497