You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hands-off supply-chain watchdog for dev machines: orchestrates multiple security scanners (Perplexity bumblebee + osv-scanner, govulncheck, NVIDIA SkillSpector) into one daily verdict — via Claude/Slack, desktop notification, or plain CLI.
Deterministic code quality gate for AI coding agents (Claude Code, Codex, pi): git hooks that block test tampering, hold the CRAP bar on changed functions, check diff coverage, secrets and dependencies. 12 languages, one config file. Optional Jev classifier for test hunks.
Fork of Google's OSV-Scanner with my fix for a stack-overflow DoS in the SPDX license parser (issue #2993, PR #3032): unbounded recursion on untrusted license expressions, now bounded with a depth limit.
Automação DevSecOps e qualidade de código não invasiva para Java e Angular via Git Hooks assíncronos. Validações SAST, SCA e linters sem alterar arquivos do projeto.
Reusable GitHub Actions workflow that scans your repo (or any external repo) with Semgrep, Gitleaks, OSV, Checkov, Trivy and SBOM, then emails a graded security report enriched with CISA KEV, FIRST EPSS and OpenSSF Scorecard.
DevSec Scanner — local-first security scanner: SAST, SCA, IaC, DAST, secret, container-image & supply-chain scans from one CLI or desktop app, unified into one report.
Deterministic broker that drives Claude Code and Grok through a detect, analyze, fix, verify loop against a target repo. Detectors find the bugs, the agents reason and patch, and no fix counts until the broker re-runs the repro itself.
Vulnfy is a lightweight, cross-platform dependency and container vulnerability scanner written in Python. It automatically detects project configuration/lock files across multiple languages and ecosystems, queries the OSV API, and generates a structured JSON vulnerability report.