edoardottt / depsdev
CLI client (and Golang module) for deps.dev API. Free access to dependencies, licenses, advisories, and other critical health and security signals for open source package versions.
☆42Updated this week
Related projects ⓘ
Alternatives and complementary repositories for depsdev
- FastCVE - fast, rich and API-based search for CVE and more (CPE, CWE, CAPEC)☆39Updated 2 months ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆55Updated 7 months ago
- ☆93Updated this week
- ☆24Updated 6 months ago
- A Server Side Request Forgery (SSRF) protection library. Made with 🖤 by Doyensec LLC.☆91Updated 6 months ago
- ☆51Updated 8 months ago
- TACOS framework structural details☆19Updated 11 months ago
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆21Updated 4 months ago
- The security workflow engine!☆73Updated this week
- An SBOM query language and associated utilities☆54Updated 9 months ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆21Updated 2 months ago
- Find which of your direct GitHub dependencies is susceptible to RepoJacking attacks☆57Updated 2 years ago
- Package retryablehttp provides a familiar HTTP client interface with automatic retries and exponential backoff☆121Updated this week
- Fast, simple library in Go to fetch CVEs from the National Vulnerability Database feeds☆25Updated last year
- ☆9Updated 6 months ago
- 🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addi…☆81Updated 11 months ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆45Updated last month
- Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners☆12Updated 3 weeks ago
- A place to systematically store software bill of materials (SBOM) documents.☆44Updated last year
- A project to visualize the software supply chain☆35Updated last year
- A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, sta…☆25Updated last year
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆27Updated 8 months ago
- Database interaction layer to store open-asset-models in sqlite3 and postgres☆16Updated this week
- ☆36Updated this week
- Unofficial but convenient Go wrapper around the NVD REST JSON API☆32Updated this week
- A documentation generator for YAML as code☆21Updated last year
- WAF bypass PoC☆43Updated last year
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.0, purl, and vers…☆96Updated this week
- SBOM Grep - search through SBOMs☆21Updated last month