Checkmarx / chainjackingLinks
Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks
β60Updated 3 years ago
Alternatives and similar repositories for chainjacking
Users that are interested in chainjacking are comparing it to the libraries listed below
Sorting:
- Manager of third-party sources of Semgrep rules πβ90Updated last year
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β41Updated 11 months ago
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β140Updated 2 weeks ago
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.β40Updated 4 years ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and versβ¦β131Updated 3 months ago
- A project to visualize the software supply chainβ54Updated 2 years ago
- boostsecurityio/lotpβ137Updated last month
- Focused malicious code detection ruleset, with a high protection-to-noise ratioβ127Updated 8 months ago
- Dependency Combobulatorβ93Updated last year
- β114Updated 2 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.β21Updated 8 months ago
- A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling,β¦β138Updated last year
- A comprehensive list of software composition analysis tools.β156Updated last month
- A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chainβ96Updated 9 months ago
- πA cutting edge context aware GraphQL API fuzzing tool!β154Updated 2 months ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)β34Updated 6 months ago
- WAF bypass PoCβ49Updated 2 years ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsβ106Updated 9 months ago
- β182Updated 6 months ago
- Secrets scanner that understands codeβ191Updated 2 years ago
- β141Updated 2 weeks ago
- Data about all known supply-chain attacks through historyβ61Updated 5 months ago
- FastCVE: A Dockerized CVE search tool with API and CLI support for security vulnerability queries.β59Updated 5 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.β156Updated last year
- Scans your Github Actions for security issuesβ86Updated last week
- Nuclei plugins to audit Chrome extensionsβ65Updated last year
- Documentation of Semgrep: a fast, open-source, static analysis tool.β45Updated this week
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).β30Updated 9 months ago
- Clean accounts over permissions in GCP infra at scaleβ71Updated 2 years ago
- Sharing software supply chain security open source projectsβ53Updated 2 years ago