
whispers
Identify hardcoded secrets in static structured text

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

Debian build files for icu 74.2 with a patch to fix CVE-2025-5222

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

A dead simple tool to sign files and verify digital signatures.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Tool to check for dependency confusion vulnerabilities in multiple package management systems

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

CLI tool to scan codebases for quantum-vulnerable cryptography

Static analysis tool to detect homoglyph substitution attacks in source code, scanning Python identifiers for visually similar Unicode characters to…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects


Public OCI-Image (docker image) Security Checker

Defense Against the Shai-Hulud Supply Chain Attack

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).