JLLeitschuh / bulk-security-pr-generator
Generate thousands of pull requests to fix widespread security vulnerabilities across GitHub.
☆34Updated 2 months ago
Alternatives and similar repositories for bulk-security-pr-generator:
Users that are interested in bulk-security-pr-generator are comparing it to the libraries listed below
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated 10 months ago
- A community collection of security reviews of open source software components.☆92Updated 10 months ago
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.☆55Updated 4 months ago
- Collection of python helper API's for interacting with LGTM.com in ways the official API doesn't support.☆23Updated 2 years ago
- Manager of third-party sources of Semgrep rules 🗂☆77Updated 5 months ago
- Documentation of Semgrep: a fast, open-source, static analysis tool.☆38Updated this week
- Externalize Java application access to protected resources as log messages.☆41Updated 8 months ago
- Mitigate security concerns of Dependency Confusion supply chain security risks☆45Updated 2 years ago
- Collect, curate, and communicate relevant security metrics for open source projects.☆63Updated 10 months ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- A Node.js vulnerability finding tool.☆95Updated 4 years ago
- A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos enginee…☆216Updated 8 months ago
- SARIF Microsoft Visual Studio Code extension☆113Updated 3 months ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- A documentation and tracking project with the goal of making package management systems more secure.☆50Updated 3 years ago
- Dependency Combobulator☆89Updated last year
- Generic SAST Library☆126Updated 2 months ago
- Security scanning & static analysis tool☆93Updated 3 months ago
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆43Updated 6 months ago
- Public disclosure channel for security vulnerabilities☆16Updated last year
- ☆176Updated 2 months ago
- GitHub Satellite 2020 workshops on finding security vulnerabilities with CodeQL for Java/JavaScript.☆209Updated 3 months ago
- ☆74Updated 4 years ago
- How GitHub Actions workflows can be hacked☆116Updated 4 months ago
- Post Processor for Facebook Static Analysis Tools.☆135Updated this week
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulne…☆31Updated 2 years ago
- CVE database☆22Updated 4 years ago
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 3 years ago
- XS-Leaks Wiki☆156Updated this week