OPEN SOURCE, OPEN TO EVERYONE

Open source. Open possibilities.

Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.

Human-curated · Discover open source4109discovered

A little curiosity. A world of open source.

THE FIRST COLLECTION
Topic: security清除
trivyaquasecurity
ADDED

Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.

Developer toolsSelf-hostedTesting & debugging
ADDED

A curated collection of Web Application Security payloads and bypasses for pentesting and CTFs, covering vulnerability descriptions, exploitation techniques, and Burp Intruder file sets.

Developer toolsAutomationTesting & debugging
nucleiprojectdiscovery
ADDED

Template-driven vulnerability scanner with a YAML DSL, community templates, and support for HTTP, DNS, TCP, SSL, WHOIS, JavaScript, headless browser, fuzzing, CI/CD integration, and multiple report formats.

Developer toolsSelf-hostedTesting & debugging
infisicalInfisical
ADDED

Infisical is an open-source platform for secrets management, certificate/PKI lifecycle, key management, and privileged access management. Features include a dashboard, CLI, SDKs and API, secret syncs and rotation, leak scanning, a Kubernetes operator, and self-hosting via Docker.

Self-hostedDeveloper toolsMonitoring & security
mcp-rematssun
ADDED

An experimental security extension for the Model Context Protocol (MCP) providing runtime evidence for tool calls via HTTP message signatures and mTLS.

AI & MLDeveloper toolsAI gateways
runtimenirmata
ADDED

Nirmata Runtime is a Kubernetes-native runtime enforcement tool using eBPF and Kyverno-style CEL policies to monitor and block file opens, execs, network traffic, protocols, and DNS queries for AI workloads.

AI & MLDeveloper toolsAI agents
pg_vault_tdelabmiriade
ADDED

pg_vault_tde is a PostgreSQL extension for Transparent Data Encryption (TDE) using AES-256-GCM. It supports key management with HashiCorp Vault, OpenBao, or local PKCS#12 wallets, and PKCS#11 HSMs. It encrypts data at the Table Access Method layer without modifying PostgreSQL core.

Developer toolsSelf-hostedBackend & APIs
agentleakyagobski
ADDED

AgentLeak is an open-source privacy testing tool for AI agents. It detects data leaks across tool calls, memory, and logs using a local Python SDK, CLI, and MCP tools, providing redacted reports and CI gates without cloud dependencies.

Developer toolsAI & MLTesting & debugging
ADDED

Web of Flaws is a structured, markdown-first catalog of web security vulnerabilities and secure code replacements designed for developers, security engineers, and AI coding agents.

Developer toolsAI & MLTesting & debugging
sopsgetsops
ADDED

SOPS is a flexible editor for encrypted files that supports multiple data formats and integrates with various cloud KMS providers and encryption tools.

Developer toolsSelf-hostedCLI & terminal
vgs-show-androidverygoodsecurity
ADDED

VGS Show Android SDK lets apps securely display sensitive data from a vault using customizable views and reveal flows, without routing raw data through client systems.

Developer toolsComponent libraries
legogo-acme
ADDED

Lego is a versatile ACME client and Go library for obtaining, renewing, and managing SSL/TLS certificates from Let's Encrypt and other CAs. It supports CLI usage and programmatic integration, featuring over 200 DNS provider plugins for automated DNS-01 challenges, plus HTTP-01 and TLS-ALPN-01 support.

Developer toolsSelf-hostedBackend & APIs

A curated list of Android security resources including tools for static/dynamic analysis, reverse engineering, fuzzing, and vulnerability scanning.

Developer toolsTesting & debugging

A curated list of open source tools for AWS security covering defensive hardening, offensive testing, auditing, DFIR, and more.

Developer toolsSelf-hostedCLI & terminal
mcp-arcademcp-tool-shop-org
ADDED

MCP Arcade is a command-line testing tool that runs a small catalog of experiments, called atoms, against MCP servers, judging results by the JSON-RPC wire and sandbox file changes rather than by tool descriptions or model prose.

Developer toolsAI & MLTesting & debugging
strixusestrix
ADDED

Strix is an open-source AI-powered penetration testing tool that uses autonomous agents to identify, validate, and fix application vulnerabilities through real proof-of-concept exploits.

Developer toolsAutomationTesting & debugging
jwtgolang-jwt
ADDED

A Go library for parsing, verifying, generating, and signing JSON Web Tokens (JWT), supporting HMAC SHA, RSA, RSA-PSS, and ECDSA algorithms with RFC 7519 compliance.

Developer toolsBackend & APIs
secretgeneratorrafaelperoco
ADDED

secretgenerator is an auditable CSPRNG‑backed credential generator for AI agents and machine‑readable pipelines. It provides stable JSON schema, NIST entropy floors, SLSA 3 and cosign signed releases, with CLI and libraries in Go, Python, Rust, and an MCP server.

Developer toolsSelf-hostedCLI & terminal
pyflowZJU-PL
ADDED

PyFlow is a research-oriented static analysis framework for Python, offering IRs, program analysis, optimization passes, security checking, supply-chain analysis, and CLI/LSP/MCP tooling.

Developer toolsAI & MLTesting & debugging
Load more projects