A vulnerability scanner for container images and filesystems
-
Updated
Sep 21, 2026 - Go
A vulnerability scanner for container images and filesystems
Pure-Rust Android decompiler and security-audit suite. DEX → Java, Hermes → JavaScript. Cross-layer taint across the React Native bridge. CycloneDX SBOM + OpenVEX. CLI and MCP. Bytecode is not a security layer.
Guided VEX authoring for OSS maintainers — from zero to a published VEX document in one command.
Deterministic, reachability-aware software composition analysis (SCA) engine — lockfile-first resolution, function- & cross-package reachability, patch-diff symbol mining, EPSS/KEV, SARIF + OpenVEX. Zero runtime dependencies.
CA9 is a local evidence engine for Python AppSec triage. It sits after scanners and before engineers waste time, proving which findings matter.
SBOM diff with supply-chain risk signals — flags new CVEs, typosquats, and young maintainers on changed deps. Built after axios (Mar 2026), Shai-Hulud, and xz.
APK / AAB / XAPK parser and security analysis library. Signing v1–v4 + ROCA / Fermat / Wiener / batch-GCD. CycloneDX SBOM with .rodata byte anchors. OpenVEX. YARA-X. Pure Rust.
Vulnerability scanner whose every result is a reproducible, signed claim. Pins the lockfile, the OSV feed, the version comparators, and the exclusions to four digests inside a signed in-toto predicate, so anyone can replay a scan byte for byte, or get a diff naming exactly which input moved.
Ultra-fast open-source code security scanner. Finds vulnerabilities across 8 languages (Rust, Go, Python, JS, TS, Java, C, C++) using SAST + taint analysis + LLM verification — fewer false positives, faster audits. Outputs Sigstore-signed SARIF, SBOM, and OpenVEX bundles for supply-chain compliance.
VEX document crawler and aggregator
CRA Article 14 dossiers from an embedded Linux build tree. Scan Yocto or Buildroot, decide affectedness with the evidence shown, emit CSAF, OpenVEX and SRP with the statutory clock running. Zero runtime dependencies, offline-capable.
Interactive prototype of an AI-assisted open-source vulnerability triage pipeline. Attribution, reachability, and OpenVEX output — synthetic data, no backend.
Agent skill for Claude Code and OpenAI Codex that triages one CVE/GHSA/OSV id against a Python repo using RBVM: CVSS, EPSS, KEV, reachability and exposure → SSVC Deployer decision → CycloneDX/OpenVEX record Dependency-Track can ingest.
The EU Cyber Resilience Act chain, end to end and offline: SBOM, VEX, vulnerability scan, Article 14 reporting, signed updates, and an Annex VII pack that prints its own gaps first. Awareness cannot be backdated once anything is filed, and a dismissal cannot remove a legal deadline.
Read, write and canonicalize OpenVEX documents in PHP
To associate your repository with the openvex topic, visit your repo's landing page and select "manage topics."