github / advisory-databaseLinks
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
☆1,912Updated this week
Alternatives and similar repositories for advisory-database
Users that are interested in advisory-database are comparing it to the libraries listed below
Sorting:
- Open source vulnerability DB and triage service.☆1,924Updated this week
- Pilot program for CVE submission through GitHub. CVE Record Submission via Pilot PRs ending 6/30/2023☆1,483Updated last month
- Open Source Package Analysis☆834Updated 3 months ago
- Actions for running CodeQL analysis☆1,305Updated this week
- This repository is used for the development of the CVE JSON record format. Releases of the CVE JSON record format will also be published …☆331Updated last week
- Global Security Database☆319Updated last year
- GitHub App to set and enforce security policies☆1,342Updated 2 weeks ago
- A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.☆1,569Updated 3 years ago
- Supply-chain Levels for Software Artifacts☆1,692Updated 3 weeks ago
- CVE cache of the official CVE List in CVE JSON 5 format☆2,150Updated this week
- Binaries for the CodeQL CLI☆848Updated 3 weeks ago
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,381Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆4,980Updated last week
- Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.☆945Updated this week
- The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnera…☆1,458Updated this week
- Resources related to GitHub Security Lab☆1,509Updated last week
- CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security☆8,539Updated this week
- A repo to conduct vulnerability enrichment.☆655Updated this week
- OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.☆1,237Updated this week
- The CodeQL extractor and libraries for Go.☆464Updated 2 years ago
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆846Updated last year
- Auditing for TLS certificates (Go code)☆1,011Updated last week
- Open Source Vulnerability schema.☆204Updated this week
- Starter workspace to use with the CodeQL extension for Visual Studio Code.☆529Updated 3 weeks ago
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆762Updated this week
- An extension for Visual Studio Code that adds rich language support for CodeQL☆459Updated last week
- LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Reque…☆1,454Updated last year
- ClusterFuzzLite - Simple continuous fuzzing that runs in CI.☆492Updated 7 months ago
- An open source threat modeling tool from OWASP☆1,142Updated last week
- NVD, Ubuntu, Alpine☆433Updated this week