bagel, a CLI that inventories security-relevant metadata on developer workstations
☆197Jul 21, 2026Updated last month
Alternatives and similar repositories for bagel
Users that are interested in bagel are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆15Sep 22, 2025Updated 11 months ago
- poutine, a supply chain vulnerability scanner for build pipelines☆518Jul 9, 2026Updated 2 months ago
- Supply Chain Security Research - Living Off The Pipeline tools☆164Jul 31, 2026Updated last month
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆379Updated this week
- Inline proxy for software package registries to provide observability and policy controls to installs.☆53Jun 5, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A GitHub Actions Supply Chain CTF / Goat☆29Apr 13, 2026Updated 5 months ago
- Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.☆61Updated this week
- Detection tells you a key is real; geiger tells you whether it's dangerous.☆36Sep 11, 2026Updated last week
- A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE☆120Updated this week
- This JavaScript CLI "undeletes' packages that have been removed from the NPM registry☆34Sep 2, 2026Updated 2 weeks ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆28Dec 5, 2025Updated 9 months ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆186Updated this week
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆77Sep 11, 2026Updated last week
- Build and query a graph database representation of source code☆487Updated this week
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- TrailAlerts is a AWS-native, serverless cloud-detection tool that lets you define simple rules as code and get rich alerts about events i…☆52May 2, 2026Updated 4 months ago
- GitHub Workflows Insights☆47Jun 27, 2026Updated 2 months ago
- AI-driven vulnerability discovery and live validation☆344May 5, 2026Updated 4 months ago
- Nova-Proximity is a MCP and Agent Skills security scanner powered with NOVA☆305Mar 26, 2026Updated 5 months ago
- Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.☆61Updated this week
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Sep 20, 2024Updated last year
- A golang-written credential harvesting framework leveraging eBPF for kernel-level monitoring with anti-detection capabilities.☆49Apr 13, 2026Updated 5 months ago
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated 3 months ago
- ☆37Apr 29, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆42Nov 13, 2025Updated 10 months ago
- A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS ac…☆165Updated this week
- Proper sandboxing for agentic coding and web browsing☆293Updated this week
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆375Jul 10, 2026Updated 2 months ago
- Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommenda…☆24Jul 6, 2026Updated 2 months ago
- ☆66May 21, 2024Updated 2 years ago
- Security configuration scanner for Claude Code☆45Updated this week
- Detect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rul…☆36Aug 5, 2026Updated last month
- A tool to check the security settings of Github Organizations.☆77Feb 9, 2026Updated 7 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Scripts and tools used by Ping Identity's corporate IT organisation☆13Sep 6, 2023Updated 3 years ago
- A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.☆33Oct 13, 2024Updated last year
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆90Sep 11, 2026Updated last week
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,210Updated this week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆72Nov 27, 2025Updated 9 months ago
- 🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness …☆117Sep 4, 2026Updated 2 weeks ago
- Data about all known supply-chain attacks through history☆79Aug 12, 2026Updated last month