19 projects
Node.js
Node.js® is a JavaScript runtime built on Chrome's V8 JavaScript engine.
51,334
9,952
$3.9B
Dependabot
Dependabot is an automated dependency update tool that helps keep software projects secure and up-to-date by monitoring dependencies, creating pull requests for version updates, and handling security vulnerabilities across multiple programming languages and package managers.
6,407
2,699
$60M
DefectDojo
DefectDojo is an open-source application vulnerability management tool that streamlines the security testing process by automating the management, triage, and reporting of security vulnerabilities. It helps organizations track and manage security findings across multiple testing tools and provides a centralized platform for vulnerability management.
2,606
312
$142M
Dependency-Track
Dependency-Track is an intelligent Component Analysis Platform that allows organizations to identify and reduce risk in their software supply chain. It continuously monitors component usage across all versions of every application in an organization's portfolio to proactively identify risk from the use of vulnerable or out-of-date components.
2,237
394
$24M
Lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
1,044
194
$828K
KubeArmor
KubeArmor is a cloud-native runtime security enforcement system that restricts the behavior (such as process execution, file access, and networking operation) of containers and nodes at the system level.
548
162
$6.3M
OWASP BLT
OWASP BLT is a collection of security tools.
523
63
$6.5M
OSV
Open source vulnerability DB and triage service.
350
132
$7.6M
Greenbone Vulnerability Manager
This repository contains the scanner component for Greenbone Community Edition.
321
35
$6.7M
ThreatMapper
ThreatMapper is an open-source cloud native security observability platform that scans, maps, and ranks vulnerabilities in running containers, images, hosts and repositories. It provides runtime analysis, threat detection, and attack path visualization across cloud native production platforms.
225
35
$15M
Copacetic
Copacetic (copa) is a tool for patching security vulnerabilities in containers.
203
58
$1.7M
cnquery
cnquery is a cloud-native security and compliance assessment tool that enables querying and analyzing system configurations, security settings, and compliance status across cloud infrastructure, containers, and Kubernetes clusters. It provides a unified interface for security scanning and infrastructure assessment.
159
30
$20M
MITRE Security Automation Framework CLI
The MITRE Security Automation Framework (SAF) CLI is a tool for executing security tests and compliance scans against systems and applications. It provides capabilities for running automated security validations, generating reports, and evaluating compliance with security benchmarks and standards.
109
17
$178M
GitHub Security Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
PHP Security Advisories Database
A database of PHP security advisories
RustSec Advisory Database
Security advisory database for Rust crates published through crates.io