A transport-agnostic OAuth 2.1 and OpenID Connect server built on OpenIddict and redb.Route, supporting multiple databases, MFA, WebAuthn, SCIM, and in-process direct-vm calls.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONDart wrapper for OpenMLS implementing Messaging Layer Security (MLS) protocol for encrypted group messaging, with TreeKEM, encrypted storage, cross‑platform Flutter support, and experimental post‑quantum ciphersuites.
An experimental security extension for the Model Context Protocol (MCP) providing runtime evidence for tool calls via HTTP message signatures and mTLS.
Nirmata Runtime is a Kubernetes-native runtime enforcement tool using eBPF and Kyverno-style CEL policies to monitor and block file opens, execs, network traffic, protocols, and DNS queries for AI workloads.
pg_vault_tde is a PostgreSQL extension for Transparent Data Encryption (TDE) using AES-256-GCM. It supports key management with HashiCorp Vault, OpenBao, or local PKCS#12 wallets, and PKCS#11 HSMs. It encrypts data at the Table Access Method layer without modifying PostgreSQL core.
Lego is a versatile ACME client and Go library for obtaining, renewing, and managing SSL/TLS certificates from Let's Encrypt and other CAs. It supports CLI usage and programmatic integration, featuring over 200 DNS provider plugins for automated DNS-01 challenges, plus HTTP-01 and TLS-ALPN-01 support.
A Go library for parsing, verifying, generating, and signing JSON Web Tokens (JWT), supporting HMAC SHA, RSA, RSA-PSS, and ECDSA algorithms with RFC 7519 compliance.
Go SDK for creating GitHub User Access Tokens for GitHub Apps with non-blocking token retrieval and optional interactive authentication.
PHP library to generate, parse, and validate security.txt files (RFC 9116). Includes CLI script for checking vulnerability disclosure practices, with validation, signature verification, and caching support.
Quivr is an opinionated RAG framework for integrating generative AI into applications. It supports any LLM, vectorstore, and file type, enabling developers to build a 'second brain' with minimal code.
Official repository of the OWASP Cheat Sheet Series, a flagship OWASP project offering concise, high-value guidance on specific application security topics for developers building and securing applications.