
slsa
Supply-chain Levels for Software Artifacts

Supply-chain Levels for Software Artifacts


Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

Issue with tough, versions prior to 0.20.0 (Multiple CVEs)

Python reference implementation of The Update Framework (TUF)

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

A software supply chain framework powered by Nix.

Anteater - CI/CD Gate Check Framework

Python source code auditing and static analysis on a large scale

Software Component Verification Standard (SCVS)

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.