* [Lego v5.4.0](https://github.com/go-acme/lego) – Let's Encrypt client and ACME library written in Go. * [Angular Lib for OpenID Connect & OAuth2 22.0.0](https://github.com/damienbod/angular-auth-oidc-client) – Library to secure Angular applications using OpenID Connect and OAuth2 with support for token refresh and modern identity providers. * [TruffleHog v3.97.0](https://github.com/trufflesecurity/trufflehog) – Powerful tool for discovering, classifying, validating, and analyzing leaked credentials. * [chezmoi v2.72.0](https://github.com/twpayne/chezmoi) – Manage dotfiles across multiple diverse machines securely. * [Cilium v1.20.0](https://github.com/cilium/cilium) – Networking, observability, and security solution with an eBPF-based dataplane. * [Web-Check 2.2.0](https://github.com/lissy93/web-check) – On-demand website intelligence dashboard that gathers network, security, and performance data to help analyze attack vectors and understand site technologies. * [Infisical v0.164.0](https://github.com/Infisical/infisical) – Secret management platform for syncing secrets and configurations across teams and infrastructure while preventing leaks. * [Cosmos v0.23.0](https://github.com/azukaar/Cosmos-Server) – Secure self-hosted home server solution for managing applications with built-in security and ease of use. * [gosec v2.29.0](https://github.com/securego/gosec) – Inspects Go source code for security issues by scanning the AST and SSA representations. * [OpenFGA v1.19.0](https://github.com/openfga/openfga) – High-performance authorization engine for modeling and enforcing fine-grained access control inspired by Google Zanzibar. * [cnspec v13.36.0](https://github.com/mondoohq/cnspec) – Cloud-native policy-as-code engine that scans infrastructure, containers, Kubernetes, cloud services, and code for vulnerabilities and misconfigurations. * [Trivy Operator v0.34.0](https://github.com/aquasecurity/trivy-operator) – Kubernetes-native toolkit that continuously scans clusters and generates vulnerability, configuration, secrets, RBAC, compliance, and SBOM reports. * [Xalgorix v4.6.0](https://github.com/xalgorix/xalgorix) – Autonomous AI pentesting platform that runs an end-to-end methodology and uses independent re-exploitation to verify and prove vulnerabilities. * [MQL v13.36.0](https://github.com/mondoohq/mql) – Cloud-native graph-based query language for querying and discovering infrastructure assets across clouds, containers, and services. * [Kyverno v1.19.0](https://github.com/kyverno/kyverno) – Policy engine for managing security, compliance, and governance in cloud native environments using policy-as-code. * [Phase Console v2.73.0](https://github.com/phasehq/console) – Platform for engineering teams to secure, manage, and deploy application secrets across environments. * [Password Pusher v2.11.0](https://github.com/pglombardo/PasswordPusher) – Securely share sensitive information with automatic expiration and deletion after a set number of views or duration. * [Trivy v0.74.0](https://github.com/aquasecurity/trivy) – Comprehensive security scanner for vulnerabilities, misconfigurations, and secrets across various targets. * [Cerbos v0.55.0](https://github.com/cerbos/cerbos) – Context-aware, YAML-defined access control with APIs for dynamic authorization decisions. * [Dradis Framework v5.3.0](https://github.com/dradis/dradis-ce) – Collaboration framework designed for InfoSec teams. * [PwnDoc v1.7.0](https://github.com/pwndoc/pwndoc) – Pentest reporting application for writing findings and generating customizable DOCX reports. * [Grype v0.117.0](https://github.com/anchore/grype) – Vulnerability scanner for container images and filesystems. * [Anubis v1.27.0](https://github.com/TecharoHQ/anubis) – Weighs the soul of connections using proof-of-work to protect resources from scraper bots. * [Beelzebub v3.9.0](https://github.com/beelzebub-labs/beelzebub) – Secure low-code honeypot framework using LLM-driven system virtualization to simulate high-interaction environments. * [hoop.dev 1.150.0](https://github.com/hoophq/hoop) – Proxy that secures and simplifies access to infrastructure with outbound-only connections and integrated SSO. * [Skylos v4.35.0](https://github.com/duriantaco/skylos) – Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities. * [MCPProxy v0.61.0](https://github.com/smart-mcp-proxy/mcpproxy-go) – Desktop proxy enabling scalable tool discovery, major token savings, and quarantine of malicious upstream servers for AI agents. * [mutant v2.4.0](https://github.com/aoiflux/mutant) – A garbage-collected programming language focused on compile-time and runtime security via encrypted bytecode. * [vm2 v3.11.7](https://github.com/patriksimek/vm2) – Sandbox for running untrusted code with controlled access to Node.js built-in modules and secure context isolation. * [Go-Landlock v0.10.0](https://github.com/landlock-lsm/go-landlock) – Go library exposing Linux Landlock sandboxing to restrict process file, network, and some IPC access. * [OpenCTI 7.260824.0](https://github.com/OpenCTI-Platform/opencti) – Platform for managing, structuring, visualizing, and sharing cyber threat intelligence using a STIX2-based knowledge schema. * [Nuclei Templates v10.4.8](https://github.com/projectdiscovery/nuclei-templates) – Community curated templates for the nuclei engine to identify security vulnerabilities in applications. * [Bearer v2.1.1](https://github.com/Bearer/bearer) – Static application security testing tool that analyzes source code and data flows to find, filter, and prioritize security and privacy risks. * [Authula v1.42.0](https://github.com/Authula/authula) – Embeddable Go library or standalone auth server with plugin-based, composable authentication and extensible hooks. * [Actions Up! v1.18.0](https://github.com/azat-io/actions-up) – CLI tool that scans workflows and updates GitHub Actions, pinning them to exact commit SHAs. * [AgentSecrets v3.2.0](https://github.com/The-17/agentsecrets) – Zero-knowledge credential infrastructure that stores and injects credentials for AI agents without ever entering agent context, enabling enforcement, auditing, and redacted responses. * [SpiceDB v1.56.1](https://github.com/authzed/spicedb) – Database for storing and querying fine-grained authorization data at scale. * [DOMPurify 3.4.14](https://github.com/cure53/DOMPurify) – Fast and tolerant XSS sanitizer for HTML, MathML, and SVG. * [OpenBao v2.6.2](https://github.com/openbao/openbao) – Software to manage, store, and distribute sensitive data like secrets, certificates, and keys. * [passbolt browser extension v5.15.0](https://github.com/passbolt/passbolt_browser_extension) – Browser extension for Firefox, Edge and Chrome providing secure cryptographic operations, random number generation, and password autofill. * [ghtkn (GH-Token) v0.4.0](https://github.com/suzuki-shunsuke/ghtkn) – CLI that generates 8-hour GitHub App user access tokens via Device Flow for secure local development. * [Brakeman v8.0.6](https://github.com/presidentbeef/brakeman) – Static analysis tool checking Ruby on Rails applications for security vulnerabilities. * [Kubescape v4.0.12](https://github.com/kubescape/kubescape) – Comprehensive security platform for managing and securing Kubernetes environments throughout the development and deployment lifecycle. * [Vigolium v0.4.0](https://github.com/vigolium/vigolium) – High-fidelity vulnerability scanner combining deterministic native scans and AI-driven agentic code audits. * [Tink Go v2.8.0](https://github.com/tink-crypto/tink-go) – Go cryptographic library providing secure, easy-to-use APIs for common crypto primitives. * [Dalec v0.22.0](https://github.com/project-dalec/dalec) – Declarative format and toolchain for building secure system packages and containers with SBOMs and provenance attestations. * [Steampipe v2.4.5](https://github.com/turbot/steampipe) – Zero-ETL tool for querying APIs and services using SQL. * [socket-proxy 1.13.0](https://github.com/wollomatic/socket-proxy) – Lightweight secure-by-default Unix socket proxy offering regex-based method allowlists, IP-based access control, and a minimal Go-only image. * [is-website-vulnerable v1.14.17](https://github.com/lirantal/is-website-vulnerable) – Detects publicly known security vulnerabilities in frontend JavaScript libraries of websites. * [CipherStash Proxy v3.0.0](https://github.com/cipherstash/proxy) – Transparent searchable encryption for existing PostgreSQL databases without SQL changes. * [express-rate-limit v8.6.2](https://github.com/express-rate-limit/express-rate-limit) – Middleware for limiting repeated requests to public APIs and endpoints. * [VICE v3.4.0](https://github.com/Webba-Creative-Technologies/vice) – Security auditing CLI for web applications supporting remote black-box scans and local white-box code audits. * [Minder v0.3.0](https://github.com/mindersec/minder) – Software supply chain security platform enforcing configurable policies, attesting artifacts, and managing repository security and dependency risk. * [vet v1.18.0](https://github.com/safedep/vet) – Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support. * [trdl v0.13.0](https://github.com/werf/trdl) – Secure software delivery system that publishes Git-based releases to a TUF repository and manages client updates. * [supautils v3.4.2](https://github.com/supabase/supautils) – Extension that secures PostgreSQL in cloud environments by managing privileges without requiring superuser access. * [Rekor v1.5.4](https://github.com/sigstore/rekor) – Immutable tamper-resistant ledger for recording and querying signed metadata in software supply chains. * [Antrea v2.5.3](https://github.com/antrea-io/antrea) – Kubernetes networking solution using Open vSwitch for L3/L4 connectivity and security. * [Powerpipe v1.5.3](https://github.com/turbot/powerpipe) – Visualize data sources and run compliance benchmarks for effective decision-making and ongoing monitoring. * [Django RLS v2.0.1](https://github.com/kdpisda/django-rls) – PostgreSQL row-level security integration for Django, enabling tenant/user policies defined with Q objects. * [sigstore framework v1.10.9](https://github.com/sigstore/sigstore) – Common code library shared by Sigstore infrastructure and Go clients providing signing interfaces and OpenID Connect support. * [Xalgorix v4.5.114](https://github.com/xalgord/xalgorix) – Autonomous AI-driven penetration testing platform that performs multi-mode scans, discovers zero-day vulnerabilities, and generates PDF reports with live dashboard alerts. * [Data security Stack for TypeScript @cipherstash/wizard@...](https://github.com/cipherstash/stack) – End-to-end field-level encryption for TypeScript apps with zero-knowledge key management and searchable encrypted queries. * [Plumber v0.4.19](https://github.com/getplumber/plumber) – CI/CD compliance scanner for GitLab pipelines * [Wazuh Dashboard Plugins v4.14.7](https://github.com/wazuh/wazuh-dashboard-plugins) – Collection of plugins that extend the Wazuh dashboard with UI panels for security events, integrity, vulnerability, and compliance monitoring. * [CrowdSec v1.8.0-rc2](https://github.com/crowdsecurity/crowdsec) – Crowdsourced security solution for detecting and blocking malicious IPs. * [osctrl v0.5.7](https://github.com/jmpsec/osctrl) – Fast, efficient osquery management server implementing the osquery remote API as a TLS endpoint. * [Greenmask v0.2.23](https://github.com/GreenmaskIO/greenmask) – Tool for database anonymization and synthetic data generation. * [Secure-Repo v1.12.7](https://github.com/step-security/secure-repo) – Automatically apply security best practices to GitHub Actions workflows, Dockerfiles, and dependency configurations. * [AuditKit v0.8.3](https://github.com/guardian-nexus/AuditKit-Community-Edition) – Multi-cloud compliance scanner that audits AWS, Azure, GCP, and M365 against standards and generates audit-ready reports. * [CoWork OS v0.5.51](https://github.com/CoWork-OS/CoWork-OS) – Security-first personal AI assistant runtime providing multi-provider model access and multi-channel messaging integrations with local-first data control. * [Snyk CLI v1.1306.4](https://github.com/snyk/cli) – Scans and monitors projects for security vulnerabilities in code, containers, dependencies, and infrastructure-as-code. * [@socketsecurity/sdk v4.1.4](https://github.com/SocketDev/socket-sdk-js) – Canonical JavaScript/TypeScript SDK for the Socket.dev API, providing package scoring, quota management, batch lookups, and dependency analysis with built-in request handling. * [Firewalla goldplus2-prod-v1.98...](https://github.com/firewalla/firewalla) – A network security appliance firmware and companion mobile and web apps for managing and monitoring home or small office networks. * [Yaklang 1.4.8-beta14](https://github.com/yaklang/yaklang) – Cybersecurity-focused domain-specific programming language with a dedicated virtual machine and IDE support. * [Tracecat 1.0.0-beta.52-rc.11](https://github.com/TracecatHQ/tracecat) – Modern automation platform for security and IT engineers with YAML templates, no-code workflows, lookup tables, and case management. * [StackRox Kubernetes Security Platform 4.9.11-rc.4](https://github.com/stackrox/stackrox) – Kubernetes security platform performing container environment risk analysis, providing visibility, runtime alerts, and hardening recommendations. * [cicd-sensor releases/v0.0.45](https://github.com/cicd-sensor/cicd-sensor) – eBPF-powered runtime security sensor for detecting supply-chain attacks in CI/CD pipelines across GitHub Actions and GitLab CI/CD with logs and evidence. * [sigstore-js @sigstore/cli@0.10.3](https://github.com/sigstore/sigstore-js) – JavaScript libraries for interacting with Sigstore signing and verification services. * [OpenSSF Best Practices Badge sbom-staging-2026082...](https://github.com/ossf/best-practices-badge) – Best Practices Badge project that defines criteria and provides a BadgeApp web application for projects to self-certify compliance and display badges. * [AEGIS aegis-v0.13.0-alpha](https://github.com/antropos17/Aegis) – Local-first EDR-style monitor tracking AI agent processes, file and network activity with per-agent risk scoring.