owasp-change / owasp-change.github.io
An Open Letter to the OWASP Board
☆106Updated last year
Related projects ⓘ
Alternatives and complementary repositories for owasp-change.github.io
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆196Updated last month
- An open-source collection of API key rotation tutorials.☆58Updated 2 months ago
- Minimum Viable Secure Product mvsp.dev☆183Updated this week
- RedFlag uses AI to identify high-risk code changes. Run it in batch mode for release candidate testing or in CI pipelines to flag PRs and…☆140Updated last week
- boostsecurityio/lotp☆100Updated 7 months ago
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆110Updated last year
- ☆109Updated last year
- Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration☆286Updated this week
- Nuclei plugins to audit Chrome extensions☆64Updated 3 months ago
- ☆63Updated last year
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Updated 5 months ago
- a hackbot proof-of-concept☆34Updated 8 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆32Updated 3 weeks ago
- 🖇️ STRIDE vs. ASVS equivalence table☆75Updated 2 months ago
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆129Updated last year
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆36Updated 10 months ago
- A tool to uncover undocumented APIs from the AWS Console.☆80Updated last month
- A curated list of Awesome Security Challenges.☆173Updated this week
- CQ, a code security scanner☆97Updated 5 months ago
- OWASP Foundation Web Respository☆19Updated 2 weeks ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆37Updated last year
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆251Updated 2 weeks ago
- boostsecurityio/poutine☆229Updated last week
- A public cloud security knowledgebase - https://www.secwiki.cloud/☆48Updated 8 months ago
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆82Updated last month
- OWASP Application Security Verification Standard 4.0 Checklist☆31Updated 5 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆79Updated this week
- Private key usage verification☆406Updated 10 months ago