Presentation and code from OWASP AppSec DC 2019 - "Testing With Your Left Foot Forward"
Repositories
jeremylong repositories
A leiningen plugin for detecting vulnerable project dependencies
Python library for audio and music analysis
Demonstrates how a malicious dependency could negatively impact the build output.
Indexer for Maven Repositories
A journey through the insecure defaults in GitHub Actions - wait who committed code to my repo?
A simple Java command-line utility to mirror the CVE XML and JSON data from NIST.
Copy of information on the Northpaw from https://sensebridge.net/projects/northpaw/instructions/
software asset scanning orchestration system
throw away project to test dependency-check false positives
A cli that can be used to query various online vulnerability sources such as the NVD or GHSA. The CLI and docker images can be used to mirror the NVD.
Java library for working with available vulnerability data sources (GitHub Security Advisories, NVD, EPSS, CISA Known Exploited Vulnerabilities, etc.)
Sonatype OSS Index - Public
Open Source Software Insights - Analysis, Comparison, Trends, Rankings of Open Source Software. Follow us on Twitter: https://twitter.com/ossinsight
An Open Letter to the OWASP Board
Java/JVM implementation of the package url spec
Phosphor: Dynamic Taint Tracking for the JVM
A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby
scanner detecting the use of JavaScript libraries with known vulnerabilities