Core functionality of OWASP CycloneDX for JavaScript (Node.js or WebBrowser) written in TypeScript.
Repositories
jeremylong repositories
Generate CycloneDX Software Bill of Materials (SBOM) from webpack bundles at compile time.
An action to delete workflow runs in a repository.
Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
The dependency-check repository has moved:
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Evaluate source control (GitHub) security posture
Gradle Plugin for Extracting Dependency Information to send to GitHub
Maven plugin for creating GitHub releases
Gradle plugin that adds a 'taskTree' task that prints task dependency tree
Mono/.NET Project to get information about an assembly. Primarily for OWASP Dependency Check
:snake: :mag: GuardDog is a CLI tool to Identify malicious PyPI and npm packages
🍻 Default formulae for the missing package manager for macOS
Proof-of-concept for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services, based on Apache Kafka.
Java program to retrieve server certificate that can be added to local keystore
Log adapter for use with JCS3 to bind to slf4j.
An extremely easy way to perform background processing in Java. Backed by persistent storage. Open and free for commercial use.
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
Presentation and code from OWASP AppSec DC 2019 - "Testing With Your Left Foot Forward"
A leiningen plugin for detecting vulnerable project dependencies