security
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
A vulnerability scanner for container images and filesystems
Operational information regarding the log4shell vulnerabilities in the Log4j logging library.
Kubetest2 is the framework for launching and running end-to-end tests on Kubernetes.
The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™
A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development
(⌐■_■) - Deep Reinforcement Learning instrumenting bettercap for WiFi pwning.
An open-source AI-first Identity and Access Management (IAM) /AI MCP gateway and auth server with web UI supporting MCP, A2A, OAuth 2.1, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA, Face ID, G…
Tutorials, examples, discussions, research proposals, and other resources related to fuzzing
🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer …
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Headless cloud-native authentication and identity management written in Go. Scales to a billion+ users. Replace Homegrown, Auth0, Okta, Firebase with better UX and DX. Passkeys, Social Sign In, OID…
OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors
A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
Bitwarden infrastructure/backend (API, database, Docker, etc).
One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser
Real-time, container-based file scanning at enterprise scale
Secure Socket Funneling - Network tool and toolkit - TCP and UDP port forwarding, SOCKS proxy, remote shell, standalone and cross platform
A simple, secure and modern file encryption tool (and Rust library) with small explicit keys, no config options, and UNIX-style composability.
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
eBPF-based Networking, Security, and Observability



