Damn Vulnerable SCA Application
-
Updated
Mar 30, 2026 - Java
Damn Vulnerable SCA Application
An inter-package analysis techinque for supply chain protection, that combines three analyses to identify malicious packages with high precision and high recall
This repo contains the technology stack and its usage for software supply chain security of a Java application
Workshop about securing the supply chain for Java applications.
Submits a build artifact to SignPath Code Integrity Platform for build integrity check and code signing.
Java-Class-Hijack: Software Supply Chain Attack for Java based on Maven Dependency Resolution and Java Classloading
To scan privacy issues in PrIvacy COnfigurable SDKs
Maven core extension for Java AppSec and DevSecOps build checks
BugFu, a tool to bugfuscate programs
Private trust registry for MCP tools — approve once, pin cryptographically (박제), detect rug-pulls forever. Self-hosted, AGPL.
AutoTriage is the control plane that turns findings from scanners and security agents into governed, reviewable and auditable decisions.
Experimental repository-local bootstrap for the Flix compiler: ./flixw <verb> downloads, digest-verifies, caches and runs the exact stock flix.jar pinned by the project. One dependency-free Java file, no Flix install, no compiler fork. Verified plugins and project tasks included.
Enterprise gateway for git-distributed AI agent skill marketplaces (Claude Code, Copilot, Cursor)
Production-grade, secure-by-default Java/Spring Boot microservice templates for the US energy sector — aligned to EO 14028, NIST SP 800-53 Rev 5 and CISA Secure by Design. OIDC (Keycloak), Vault secrets, OpenTelemetry, CycloneDX SBOM, STRIDE threat models and CVE-gated CI.
MCP 工具面安全扫描器(Java)—— 指纹化并锁定 MCP 服务器工具定义,检测 schema 投毒 / 工具影子 / rug pull,可作 CI 门禁
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
Rewrites source code so it still compiles and passes tests for humans and machines, but degrades as AI training data. CLI, GitHub Action, and pre-commit hook. Java 21 first; Python/JS support.
Java library which implements the Java object model for SPDX and provides useful helper functions
Reference infrastructure taking a distributed system from git push to a monitored, zero-downtime Kubernetes deployment — Spring Boot/Kafka services, Terraform/Ansible provisioning, GitOps delivery via Flux, and a signed, attested supply chain
To associate your repository with the supply-chain-security topic, visit your repo's landing page and select "manage topics."