The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebases using a variety of static analysis security testing (SAST) tools and generate reports to evaluate those tools.
☆173Mar 12, 2024Updated 2 years ago
Alternatives and similar repositories for ossf-cve-benchmark
Users that are interested in ossf-cve-benchmark are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆11Jun 8, 2021Updated 5 years ago
- Present ZAProxy results in GitHub Advanced Security☆17May 24, 2024Updated 2 years ago
- Original workshops and staging area for new ones☆16Jul 3, 2025Updated last year
- Depstubber generates type-correct stubs for Go dependencies, for use in testing☆18Mar 21, 2025Updated last year
- GitHub Action for filtering Code Scanning alerts by path and id☆35Jul 22, 2026Updated last month
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Integrate CodeQL into CI/CD pipelines, using the CodeQL CLI Bundle for Automated Code Scanning☆22Jun 9, 2026Updated 2 months ago
- This repo demonstrates how to use the GitHub Code Scanning API to export all the alerts in an organization to a CSV file☆18Jul 12, 2023Updated 3 years ago
- GitHub Advanced Security Pull Request Security Team required review GitHub App☆36Aug 11, 2026Updated 2 weeks ago
- ☆12Jul 26, 2022Updated 4 years ago
- This repository contains a list of papers about software supply chain☆29May 22, 2024Updated 2 years ago
- LLM <-- MCP --> CodeQL( AST | CFG | CLI | LSP )☆33Updated this week
- Public disclosure channel for security vulnerabilities☆16Nov 17, 2025Updated 9 months ago
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆21Jan 28, 2021Updated 5 years ago
- An eBPF-based security research tool that demonstrates offensive techniques including network discovery, file system monitoring, process …☆40Jul 4, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web…☆822Updated this week
- GitHub Secret Scanning Auto Remediator (GSSAR)☆50Aug 3, 2026Updated 3 weeks ago
- GitHub Code Scanning Mean Time to Remediate (GCSMTTR)☆14Jun 27, 2023Updated 3 years ago
- SARIF Microsoft Visual Studio Code extension☆139Feb 14, 2026Updated 6 months ago
- This repository contains CodeQL queries and libraries which support various Coding Standards.☆224Updated this week
- REST API Fuzz Testing (RAFT): Source code for self-hosted service developed for Azure, including the API, orchestration engine, and defau…☆263Jan 13, 2022Updated 4 years ago
- [Deprecated] GitHub's Field Team's CodeQL Custom Queries, Suites, and Configurations. See GitHubSecurityLab/CodeQL-Community-Packs instea…☆85May 1, 2024Updated 2 years ago
- QEMU to drcov trace file☆12Nov 21, 2020Updated 5 years ago
- A tool for analyzing the attack surface of an application☆19Mar 5, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Go tool to declaratively bump dependencies.☆13Jul 9, 2026Updated last month
- OWASP ZAP add-on to detect reflected parameter vulnerabilities efficiently☆12Feb 19, 2021Updated 5 years ago
- GitHub Advanced Security Python Toolkit☆14Aug 3, 2026Updated 3 weeks ago
- Coverage-guided, in-process fuzzing for the JVM☆1,253Updated this week
- A JavaScript components vulnerability scanner, based on RetireJS☆36Jun 8, 2020Updated 6 years ago
- A Python module that enables the automation of Firefox☆33Aug 14, 2026Updated 2 weeks ago
- Documenting your Threat Models with HCL☆463Updated this week
- Focus SAST scans (with CodeQL) on just the changed parts of your monorepo, split up as you define☆16Jul 17, 2026Updated last month
- Salesforce Policy Deviation Checker☆30Sep 30, 2020Updated 5 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A CVE Heatmap Using CalPlot☆98Jan 25, 2021Updated 5 years ago
- ☆33Jan 17, 2024Updated 2 years ago
- ☆84Apr 26, 2024Updated 2 years ago
- A dataset of software supply chain compromises. Please help us maintain it!☆130Sep 16, 2022Updated 3 years ago
- Helping allocate resources to secure the critical open source projects we all depend on.☆410May 8, 2025Updated last year
- CVE, reports, research☆15Mar 17, 2021Updated 5 years ago
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆141Aug 19, 2026Updated last week