* [Anubis v1.28.0](https://github.com/TecharoHQ/anubis) – Weighs the soul of connections using proof-of-work to protect resources from scraper bots. * [TruffleHog v3.99.0](https://github.com/trufflesecurity/trufflehog) – Powerful tool for discovering, classifying, validating, and analyzing leaked credentials. * [Nuclei Templates v10.5.0](https://github.com/projectdiscovery/nuclei-templates) – Community curated templates for the nuclei engine to identify security vulnerabilities in applications. * [cnspec v14.5.0](https://github.com/mondoohq/cnspec) – Cloud-native policy-as-code engine that scans infrastructure, containers, Kubernetes, cloud services, and code for vulnerabilities and misconfigurations. * [MQL v14.5.0](https://github.com/mondoohq/mql) – Cloud-native graph-based query language for querying and discovering infrastructure assets across clouds, containers, and services. * [Tracecat 1.1.0](https://github.com/TracecatHQ/tracecat) – Modern automation platform for security and IT engineers with YAML templates, no-code workflows, lookup tables, and case management. * [EVE 17.9.0](https://github.com/lf-edge/eve) – Edge virtualization engine providing hardware-assisted virtualization and resource partitioning for on-premises edge devices. * [Ship Safe v11.0.0](https://github.com/asamassekou10/ship-safe) – AI-powered security platform that scans codebases for secrets, vulnerabilities, CVEs, and generates prioritized remediation plans. * [Meme v2.0.0](https://github.com/nhovongoc0-max/meme-radar) – Local read-only multi-chain meme candidate scanner with GMGN-backed HTTP API access and manual review workflow. * [Skylos v4.47.0](https://github.com/duriantaco/skylos) – Privacy-first hybrid static-analysis tool for Python, TypeScript, and Go that detects dead code, secrets, and security vulnerabilities. * [vet v1.20.0](https://github.com/safedep/vet) – Enterprise-grade software supply chain security tool with real-time malicious package detection and policy as code support. * [OpenFGA v1.22.0](https://github.com/openfga/openfga) – High-performance authorization engine for modeling and enforcing fine-grained access control inspired by Google Zanzibar. * [Infisical v0.166.0](https://github.com/Infisical/infisical) – Secret management platform for syncing secrets and configurations across teams and infrastructure while preventing leaks. * [Trivy Operator v0.35.0](https://github.com/aquasecurity/trivy-operator) – Kubernetes-native toolkit that continuously scans clusters and generates vulnerability, configuration, secrets, RBAC, compliance, and SBOM reports. * [osctrl v0.6.0](https://github.com/jmpsec/osctrl) – Fast, efficient osquery management server implementing the osquery remote API as a TLS endpoint. * [gowitness 3.2.2](https://github.com/sensepost/gowitness) – A Go-based website screenshot utility that uses Chrome Headless to capture web pages from the command line with optional reporting and saved results. * [Authula v1.48.0](https://github.com/Authula/authula) – Embeddable Go library or standalone auth server with plugin-based, composable authentication and extensible hooks. * [Plumber v0.6.0](https://github.com/getplumber/plumber) – CI/CD compliance scanner for GitLab pipelines * [@socketsecurity/sdk v4.2.0](https://github.com/SocketDev/socket-sdk-js) – Canonical JavaScript/TypeScript SDK for the Socket.dev API, providing package scoring, quota management, batch lookups, and dependency analysis with built-in request handling. * [HotCell v1.1.0](https://github.com/basecamp/hotcell) – Rails-oriented HotCell sidecar isolates untrusted computation in an unprivileged container with strict resource limits and file-descriptor based RPC. * [OpenCTI 7.261008.0](https://github.com/OpenCTI-Platform/opencti) – Platform for managing, structuring, visualizing, and sharing cyber threat intelligence using a STIX2-based knowledge schema. * [portchecker.io v4.2.0](https://github.com/dsgnr/portchecker.io) – API for checking port availability on specified hostnames or IP addresses to assist network troubleshooting and firewall validation. * [Grype v0.120.1](https://github.com/anchore/grype) – Vulnerability scanner for container images and filesystems. * [Password Pusher v2.14.2](https://github.com/pglombardo/PasswordPusher) – Securely share sensitive information with automatic expiration and deletion after a set number of views or duration. * [express-rate-limit v8.7.1](https://github.com/express-rate-limit/express-rate-limit) – Middleware for limiting repeated requests to public APIs and endpoints. * [secure-json-parse v4.1.1](https://github.com/fastify/secure-json-parse) – JSON.parse() drop-in replacement that protects against prototype poisoning via \_\_proto\_\_ and constructor.prototype keys. * [hoop.dev 1.234.0](https://github.com/hoophq/hoop) – Proxy that secures and simplifies access to infrastructure with outbound-only connections and integrated SSO. * [Go-TPM tools v0.4.11](https://github.com/google/go-tpm-tools) – High-level Go packages providing APIs for interacting with TPM 2.0 devices. * [Phase Console v2.77.3](https://github.com/phasehq/console) – Platform for engineering teams to secure, manage, and deploy application secrets across environments. * [Data security Stack for TypeScript stack-encrypt-derive...](https://github.com/cipherstash/stack) – End-to-end field-level encryption for TypeScript apps with zero-knowledge key management and searchable encrypted queries. * [Xalgorix v4.6.153](https://github.com/xalgorix/xalgorix) – Autonomous AI pentesting platform that runs an end-to-end methodology and uses independent re-exploitation to verify and prove vulnerabilities. * [CoWork OS v0.5.60](https://github.com/CoWork-OS/CoWork-OS) – Security-first personal AI assistant runtime providing multi-provider model access and multi-channel messaging integrations with local-first data control. * [ReVens 1.5.6](https://github.com/Jakiboy/ReVens) – Windows-based, AI-powered all-in-one reverse engineering package manager for malware analysis, penetration testing, and education. * [js-x-ray @nodesecure/js-x-ray...](https://github.com/NodeSecure/js-x-ray) – JavaScript AST analysis tool for identifying potentially malicious code patterns. * [Yaklang 1.4.9-beta2](https://github.com/yaklang/yaklang) – Cybersecurity-focused domain-specific programming language with a dedicated virtual machine and IDE support. * [AEGIS aegis-v0.19.2-beta](https://github.com/antropos17/Aegis) – Local-first EDR-style monitor tracking AI agent processes, file and network activity with per-agent risk scoring. * [Firewalla gold-alpha-v1.984.00...](https://github.com/firewalla/firewalla) – A network security appliance firmware and companion mobile and web apps for managing and monitoring home or small office networks.