Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.
-
Updated
Jan 28, 2026 - JavaScript
Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.
Runtime dependency behavior monitor for Node.js - detects software supply-chain abuse
Preventing sensitive data from being pushed to a repository | Removing traces of the sensitive data | GitHub vulnerability alerts| Fixing vulnerable dependencies | Security policy | .gitignore | Tracing sensitive data
🔍 Demonstrate and validate the `addressof` and `fakeobj` primitives in the V8 sandbox for advanced security research on CVE-2025-6554.
Add a description, image, and links to the open-source-security topic page so that developers can more easily learn about it.
To associate your repository with the open-source-security topic, visit your repo's landing page and select "manage topics."