* [Anubis v1.28.0](https://github.com/TecharoHQ/anubis) – Weighs the soul of connections using proof-of-work to protect resources from scraper bots. * [TruffleHog v3.99.0](https://github.com/trufflesecurity/trufflehog) – Powerful tool for discovering, classifying, validating, and analyzing leaked credentials. * [Nuclei Templates v10.5.0](https://github.com/projectdiscovery/nuclei-templates) – Community curated templates for the nuclei engine to identify security vulnerabilities in applications. * [Web-Check 2.3.0](https://github.com/lissy93/web-check) – On-demand website intelligence dashboard that gathers network, security, and performance data to help analyze attack vectors and understand site technologies. * [Brakeman v8.1.0](https://github.com/presidentbeef/brakeman) – Static analysis tool checking Ruby on Rails applications for security vulnerabilities. * [chezmoi v2.73.0](https://github.com/twpayne/chezmoi) – Manage dotfiles across multiple diverse machines securely. * [Lego v5.5.0](https://github.com/go-acme/lego) – Let's Encrypt client and ACME library written in Go. * [Tracecat 1.0.0](https://github.com/TracecatHQ/tracecat) – Modern automation platform for security and IT engineers with YAML templates, no-code workflows, lookup tables, and case management. * [cnspec v14.5.0](https://github.com/mondoohq/cnspec) – Cloud-native policy-as-code engine that scans infrastructure, containers, Kubernetes, cloud services, and code for vulnerabilities and misconfigurations. * [MQL v14.5.0](https://github.com/mondoohq/mql) – Cloud-native graph-based query language for querying and discovering infrastructure assets across clouds, containers, and services. * [EVE 17.9.0](https://github.com/lf-edge/eve) – Edge virtualization engine providing hardware-assisted virtualization and resource partitioning for on-premises edge devices. * [Ship Safe v11.0.0](https://github.com/asamassekou10/ship-safe) – AI-powered security platform that scans codebases for secrets, vulnerabilities, CVEs, and generates prioritized remediation plans. * [Meme v2.0.0](https://github.com/nhovongoc0-max/meme-radar) – Local read-only multi-chain meme candidate scanner with GMGN-backed HTTP API access and manual review workflow. * [Skylos v4.47.0](https://github.com/duriantaco/skylos) – Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities. * [vet v1.20.0](https://github.com/safedep/vet) – Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support. * [OpenFGA v1.22.0](https://github.com/openfga/openfga) – High-performance authorization engine for modeling and enforcing fine-grained access control inspired by Google Zanzibar. * [Infisical v0.166.0](https://github.com/Infisical/infisical) – Secret management platform for syncing secrets and configurations across teams and infrastructure while preventing leaks. * [Trivy Operator v0.35.0](https://github.com/aquasecurity/trivy-operator) – Kubernetes-native toolkit that continuously scans clusters and generates vulnerability, configuration, secrets, RBAC, compliance, and SBOM reports. * [Grype v0.120.0](https://github.com/anchore/grype) – Vulnerability scanner for container images and filesystems. * [Trivy v0.75.0](https://github.com/aquasecurity/trivy) – Comprehensive security scanner for vulnerabilities, misconfigurations, and secrets across various targets. * [Cerbos v0.56.0](https://github.com/cerbos/cerbos) – Context-aware, YAML-defined access control with APIs for dynamic authorization decisions. * [UTMStack v12.0.0](https://github.com/utmstack/UTMStack) – Enterprise-ready SIEM and XDR platform offering real-time log correlation, threat intelligence, and incident response. * [Shuffle Automation v2.3.0](https://github.com/Shuffle/Shuffle) – General-purpose security automation platform for security teams, offering workflow editor, OpenAPI-based app creation, and resource sharing. * [Step CLI v0.31.0](https://github.com/smallstep/cli) – Easy-to-use CLI for building, operating, and automating PKI systems and common X.509, JWT, and crypto workflows. * [Phase Console v2.77.0](https://github.com/phasehq/console) – Platform for engineering teams to secure, manage, and deploy application secrets across environments. * [Interactsh v1.4.0](https://github.com/projectdiscovery/interactsh) – Out-of-band interaction gathering server and client library. * [OpenBao v2.7.0](https://github.com/openbao/openbao) – Software to manage, store, and distribute sensitive data like secrets, certificates, and keys. * [SafeLine v9.4.2](https://github.com/chaitin/SafeLine) – Self-hosted web application firewall and reverse proxy that protects web apps from various attacks. * [Dradis Framework v5.4.0](https://github.com/dradis/dradis-ce) – Collaboration framework designed for InfoSec teams. * [Password Pusher v2.14.0](https://github.com/pglombardo/PasswordPusher) – Securely share sensitive information with automatic expiration and deletion after a set number of views or duration. * [DevSec Linux Baseline 2.11.0](https://github.com/dev-sec/linux-baseline) – InSpec compliance profile enforcing consistent hardening checks across Linux systems. * [OWASP secureCodeBox v5.9.0](https://github.com/secureCodeBox/secureCodeBox) – Kubernetes-based modular toolchain for continuous security scanning of software projects. * [AuditKit v1.0.0](https://github.com/guardian-nexus/AuditKit-Community-Edition) – Multi-cloud compliance scanner that audits AWS, Azure, GCP, and M365 against standards and generates audit-ready reports. * [gowitness 3.2.0](https://github.com/sensepost/gowitness) – A Go-based website screenshot utility that uses Chrome Headless to capture web pages from the command line with optional reporting and saved results. * [Whitelist Bypass v0.4.0](https://github.com/kulikov0/whitelist-bypass) – Tunnels internet traffic through VK Call and Yandex Telemost video platforms to bypass government whitelist censorship. * [osctrl v0.6.0](https://github.com/jmpsec/osctrl) – Fast, efficient osquery management server implementing the osquery remote API as a TLS endpoint. * [Authula v1.48.0](https://github.com/Authula/authula) – Embeddable Go library or standalone auth server with plugin-based, composable authentication and extensible hooks. * [Plumber v0.6.0](https://github.com/getplumber/plumber) – CI/CD compliance scanner for GitLab pipelines * [@socketsecurity/sdk v4.2.0](https://github.com/SocketDev/socket-sdk-js) – Canonical JavaScript/TypeScript SDK for the Socket.dev API, providing package scoring, quota management, batch lookups, and dependency analysis with built-in request handling. * [HotCell v1.1.0](https://github.com/basecamp/hotcell) – Rails-oriented HotCell sidecar isolates untrusted computation in an unprivileged container with strict resource limits and file-descriptor based RPC. * [OpenCTI 7.261008.0](https://github.com/OpenCTI-Platform/opencti) – Platform for managing, structuring, visualizing, and sharing cyber threat intelligence using a STIX2-based knowledge schema. * [portchecker.io v4.2.0](https://github.com/dsgnr/portchecker.io) – API for checking port availability on specified hostnames or IP addresses to assist network troubleshooting and firewall validation. * [express-rate-limit v8.7.1](https://github.com/express-rate-limit/express-rate-limit) – Middleware for limiting repeated requests to public APIs and endpoints. * [MCPProxy v0.70.0](https://github.com/smart-mcp-proxy/mcpproxy-go) – Desktop proxy enabling scalable tool discovery, major token savings, and quarantine of malicious upstream servers for AI agents. * [Kontext v1.10.0](https://github.com/kontext-security/kontext) – Kontext places local policy between AI agents and the tools they call, evaluating, enforcing, and recording authorization decisions before consequential actions run. * [hoop.dev 1.198.0](https://github.com/hoophq/hoop) – Proxy that secures and simplifies access to infrastructure with outbound-only connections and integrated SSO. * [Kubescape v4.0.15](https://github.com/kubescape/kubescape) – Comprehensive security platform for managing and securing Kubernetes environments throughout the development and deployment lifecycle. * [Xalgorix v4.6.118](https://github.com/xalgorix/xalgorix) – Autonomous AI pentesting platform that runs an end-to-end methodology and uses independent re-exploitation to verify and prove vulnerabilities. * [Actions Up! v1.21.0](https://github.com/azat-io/actions-up) – CLI tool that scans workflows and updates GitHub Actions, pinning them to exact commit SHAs. * [VICE v3.5.0](https://github.com/Webba-Creative-Technologies/vice) – Security auditing CLI for web applications supporting remote black-box scans and local white-box code audits. * [DOMPurify 3.4.16](https://github.com/cure53/DOMPurify) – Fast and tolerant XSS sanitizer for HTML, MathML, and SVG. * [rate-limiter-flexible v11.2.1](https://github.com/animir/node-rate-limiter-flexible) – Counts and limits actions by key to protect against DDoS and brute force attacks. * [mutant v2.5.0](https://github.com/aoiflux/mutant) – A garbage-collected programming language focused on compile-time and runtime security via encrypted bytecode. * [Steampipe v2.4.7](https://github.com/turbot/steampipe) – Zero-ETL tool for querying APIs and services using SQL. * [Cilium v1.19.8](https://github.com/cilium/cilium) – Networking, observability, and security solution with an eBPF-based dataplane. * [passbolt browser extension v5.16.0](https://github.com/passbolt/passbolt_browser_extension) – Browser extension for Firefox, Edge and Chrome providing secure cryptographic operations, random number generation, and password autofill. * [beyond v1.9.0](https://github.com/presbrey/beyond) – BeyondCorp-inspired HTTPS/SSO access proxy that controls access to internal services beyond your perimeter using OpenID Connect, OAuth2, or SAML. * [Warden v0.20.0](https://github.com/stephnangue/warden) – Runtime access gateway enforcing identity-based egress policies and issuing ephemeral credentials so workloads have no long-lived secrets * [SpiceDB Operator v1.27.0](https://github.com/authzed/spicedb-operator) – Kubernetes operator that manages and scales SpiceDB clusters and automates datastore migrations. * [SpiceDB v1.56.2](https://github.com/authzed/spicedb) – Database for storing and querying fine-grained authorization data at scale. * [trust-manager v0.25.0](https://github.com/cert-manager/trust-manager) – Kubernetes/OpenShift operator that combines trusted certificate sources into a distributable trust bundle for applications. * [react-native-secure-webview v0.1.0](https://github.com/adnxy/react-native-secure-webview) – Fabric-native secure WebView for React Native controlled web flows, validating navigations against an exact origin allowlist and emitting deep-link events instead of loading custom schemes. * [secure-json-parse v4.1.1](https://github.com/fastify/secure-json-parse) – JSON.parse() drop-in replacement that protects against prototype poisoning via \_\_proto\_\_ and constructor.prototype keys. * [Go-TPM tools v0.4.11](https://github.com/google/go-tpm-tools) – High-level Go packages providing APIs for interacting with TPM 2.0 devices. * [Data security Stack for TypeScript stack-encrypt-derive...](https://github.com/cipherstash/stack) – End-to-end field-level encryption for TypeScript apps with zero-knowledge key management and searchable encrypted queries. * [ghtkn (GH-Token) v0.4.1](https://github.com/suzuki-shunsuke/ghtkn) – CLI that generates 8-hour GitHub App user access tokens via Device Flow for secure local development. * [AgentSecrets v3.3.2](https://github.com/The-17/agentsecrets) – Zero-knowledge credential infrastructure that stores and injects credentials for AI agents without ever entering agent context, enabling enforcement, auditing, and redacted responses. * [Wazuh Dashboard Plugins v4.14.8](https://github.com/wazuh/wazuh-dashboard-plugins) – Collection of plugins that extend the Wazuh dashboard with UI panels for security events, integrity, vulnerability, and compliance monitoring. * [entitlements-app v1.2.6](https://github.com/github/entitlements-app) – Ruby gem providing git-managed LDAP group configuration and access provisioning for identity and access management. * [WebAuthn Library v0.18.2](https://github.com/go-webauthn/webauthn) – FIDO2-conformant passkey and authentication backend for Go applications. * [Powerpipe v1.5.5](https://github.com/turbot/powerpipe) – Visualize data sources and run compliance benchmarks for effective decision-making and ongoing monitoring. * [Minder v0.3.2](https://github.com/mindersec/minder) – Software supply chain security platform enforcing configurable policies, attesting artifacts, and managing repository security and dependency risk. * [Go-Landlock v0.10.1](https://github.com/landlock-lsm/go-landlock) – Go library exposing Linux Landlock sandboxing to restrict process file, network, and some IPC access. * [CoWork OS v0.5.60](https://github.com/CoWork-OS/CoWork-OS) – Security-first personal AI assistant runtime providing multi-provider model access and multi-channel messaging integrations with local-first data control. * [ReVens 1.5.6](https://github.com/Jakiboy/ReVens) – Windows-based, AI-powered all-in-one reverse engineering package manager for malware analysis, penetration testing, and education. * [js-x-ray @nodesecure/js-x-ray...](https://github.com/NodeSecure/js-x-ray) – JavaScript AST analysis tool for identifying potentially malicious code patterns. * [Greenmask v0.2.25](https://github.com/GreenmaskIO/greenmask) – Tool for database anonymization and synthetic data generation. * [Go SDK for OpenFGA v0.8.3](https://github.com/openfga/go-sdk) – Autogenerated Go client wrapping a fine-grained authorization API for modeling and checking relationships. * [Snyk CLI v1.1307.4](https://github.com/snyk/cli) – Scans and monitors projects for security vulnerabilities in code, containers, dependencies, and infrastructure-as-code. * [supautils v3.4.4](https://github.com/supabase/supautils) – Extension that secures PostgreSQL in cloud environments by managing privileges without requiring superuser access. * [Distributed Motion Surveillance Security System (DMS³) 1.4.9](https://github.com/richbl/go-distributed-motion-s3) – Go-based distributed video surveillance system integrating third-party motion detectors for SBCs with server-client coordination, local processing, and event reporting. * [AppArmor.d v0.4914.0](https://github.com/roddhjav/apparmor.d) – Set of over 1500 AppArmor profiles to confine core Linux system services, desktop environments, and user processes. * [Anchore Kubernetes Inventory v1.8.5](https://github.com/anchore/k8s-inventory) – Periodic Kubernetes API poller reporting containers, images, pods, nodes and namespaces currently in use. * [Thunderbird User.JS v140.3](https://github.com/HorlogeSkynet/thunderbird-user.js) – Thunderbird user.js template providing privacy, security, and anti-fingerprinting settings while minimizing functionality loss in email-focused use. * [Kubernetes security diagram (cheatsheet) v2026.09.5](https://github.com/kubesec-diagram/kubesec-diagram.github.io) – Human-made Kubernetes security diagram cheatsheet that helps teams browse and discuss security concepts across Kubernetes components and controls. * [Yaklang 1.4.9-beta1](https://github.com/yaklang/yaklang) – Cybersecurity-focused domain-specific programming language with a dedicated virtual machine and IDE support. * [Swifty v1.0.0-alpha.1](https://github.com/swiftyapp/swifty) – Offline-first password manager that stores and encrypts vault data locally with optional TOTP and Google Drive synchronization. * [AEGIS aegis-v0.19.2-beta](https://github.com/antropos17/Aegis) – Local-first EDR-style monitor tracking AI agent processes, file and network activity with per-agent risk scoring. * [OpenSSF Best Practices Badge sbom-production-2026...](https://github.com/ossf/best-practices-badge) – Best Practices Badge project that defines criteria and provides a BadgeApp web application for projects to self-certify compliance and display badges. * [Rowel v1.0.0-alpha.7](https://github.com/fwdai/rowel) – Offline-first password manager for macOS, Windows, and Linux with locally encrypted vault storage, strong password generation, TOTP support, and optional Google Drive sync. * [Firewalla gold-alpha-v1.984.00...](https://github.com/firewalla/firewalla) – A network security appliance firmware and companion mobile and web apps for managing and monitoring home or small office networks. * [Clouditor Community Edition v2.0.0-alpha.20](https://github.com/clouditor/clouditor) – Continuous cloud-assurance platform that evaluates cloud configurations for security and compliance against standards like C5 and CSA CCM.