JLLeitschuh / bulk-security-pr-generator
Generate thousands of pull requests to fix widespread security vulnerabilities across GitHub.
☆34Updated last month
Alternatives and similar repositories for bulk-security-pr-generator:
Users that are interested in bulk-security-pr-generator are comparing it to the libraries listed below
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆142Updated last year
- A community collection of security reviews of open source software components.☆93Updated last year
- Manager of third-party sources of Semgrep rules 🗂☆81Updated 8 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆40Updated this week
- Collection of python helper API's for interacting with LGTM.com in ways the official API doesn't support.☆23Updated 2 years ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆23Updated 9 months ago
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.☆56Updated 6 months ago
- Externalize Java application access to protected resources as log messages.☆41Updated 10 months ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆59Updated 2 weeks ago
- CodeQL queries developed by Trail of Bits☆89Updated 3 months ago
- A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos enginee…☆220Updated 10 months ago
- ☆70Updated 3 years ago
- Generic SAST Library☆130Updated 4 months ago
- Security scanning & static analysis tool☆94Updated 5 months ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 3 weeks ago
- Collection of community-driven CodeQL query, library and extension packs☆145Updated 3 weeks ago
- SARIF Microsoft Visual Studio Code extension☆113Updated last week
- Prepackaged and precompiled github codeql container for rapid analysis, deployment and development.☆115Updated last year
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆44Updated 9 months ago
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆74Updated last week
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 3 years ago
- OSS-Fuzz vulnerabilities for OSV.☆149Updated this week
- ☆184Updated 4 months ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.1, purl, and vers…☆112Updated 3 weeks ago
- A Simple command line tool that helps checking web applications to identify insecure deserialization vulnerabilities.☆24Updated 5 years ago
- CVE database☆22Updated 4 years ago
- Trail of Bits Testing Handbook☆66Updated 3 weeks ago
- Scan pypi for typosquatting☆38Updated 2 years ago
- *Unofficial* lgtm.com CLI — Use at your own risk. Also don't add more than 3K projects to "My projects" list.☆13Updated 3 years ago