awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

27 repositorios

Awesome GitHub RepositoriesDependency Vulnerability Scanners

Tools that analyze project dependencies to detect known security vulnerabilities.

Distinguishing note: Focuses on supply chain security and dependency auditing rather than general application security.

Explore 27 awesome GitHub repositories matching security & cryptography · Dependency Vulnerability Scanners. Refine with filters or upvote what's useful.

Awesome Dependency Vulnerability Scanners GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • chalarangelo/30-seconds-of-codeAvatar de Chalarangelo

    Chalarangelo/30-seconds-of-code

    128,121Ver en GitHub↗

    30-seconds-of-code is a comprehensive knowledge base and programming snippet library designed to support software engineering education and professional development. It provides a curated collection of reusable code units and technical guides that help developers master core language mechanics, design patterns, and architectural philosophies. The project distinguishes itself by offering a wide-ranging library of algorithmic solutions and web development patterns that are organized into modular, independently testable units. It emphasizes functional programming paradigms and declarative logic,

    Provides tools that analyze project dependencies to detect known security vulnerabilities.

    JavaScriptastroawesome-listcss
    Ver en GitHub↗128,121
  • addyosmani/agent-skillsAvatar de addyosmani

    addyosmani/agent-skills

    60,849Ver en GitHub↗

    Agent-skills is a collection of structured instructions and behavioral personas designed to standardize how AI coding agents perform engineering tasks. It functions as a workflow orchestrator that maps natural language intent to repeatable technical sequences and verification checklists. The project distinguishes itself through the use of specialized markdown-defined roles, such as security auditors or test engineers, to apply targeted domain expertise. It employs an evidence-based verification model that requires runtime data or passing tests as mandatory exit criteria to ensure AI-generated

    Evaluates dependency audit results based on severity and reachability to prioritize critical updates.

    Shellagent-skillsantigravityantigravity-ide
    Ver en GitHub↗60,849
  • keygraphhq/shannonAvatar de KeygraphHQ

    KeygraphHQ/shannon

    44,672Ver en GitHub↗

    Shannon is an integrated security platform designed for autonomous penetration testing, static and dynamic analysis, and automated vulnerability remediation within self-hosted, private infrastructure. It functions as a unified security suite that orchestrates the entire lifecycle of vulnerability management, from initial discovery and reachability prioritization to the generation and verification of code-level patches. The platform distinguishes itself through its agentic approach to security, deploying autonomous agents to execute both black-box and white-box exploits against running applica

    Identifies security flaws in third-party dependencies and determines reachability from attacker-controlled inputs.

    TypeScriptpenetration-testingpentestingsecurity-audit
    Ver en GitHub↗44,672
  • viatsko/awesome-vscodeAvatar de viatsko

    viatsko/awesome-vscode

    28,754Ver en GitHub↗

    This project is a curated directory of resources, extensions, and themes designed to extend the functionality of the Visual Studio Code editor. It serves as a comprehensive index for developers seeking to enhance their coding environment, offering a structured collection of community-driven tools that streamline development workflows and improve editor productivity. The directory distinguishes itself by organizing a vast ecosystem of plugins into logical categories, ranging from language-specific intelligence and version control integrations to advanced productivity utilities. It highlights t

    Identify security vulnerabilities in project components to ensure supply chain safety.

    JavaScriptawesomeawesome-listlist
    Ver en GitHub↗28,754
  • voltagent/awesome-claude-code-subagentsAvatar de VoltAgent

    VoltAgent/awesome-claude-code-subagents

    21,906Ver en GitHub↗

    This project provides a framework for managing multi-agent systems, designed to automate complex software development, infrastructure, and business workflows. It functions as a multi-agent workflow orchestrator that routes tasks to domain-specific workers while maintaining state persistence and infrastructure automation. By leveraging large language models, the system decomposes high-level objectives into actionable plans, ensuring that complex operations are executed with consistency and reliability. The framework distinguishes itself through its hierarchical agent registry and policy-driven

    Scans project dependencies to identify security vulnerabilities, version conflicts, and license issues.

    Shellai-agent-frameworkai-agent-toolsai-agents
    Ver en GitHub↗21,906
  • valeriansaliou/sonicAvatar de valeriansaliou

    valeriansaliou/sonic

    21,249Ver en GitHub↗

    Sonic is a high-performance, lightweight search backend designed to provide real-time full-text search and autocomplete capabilities for applications. It functions as a persistent indexing server that maps text terms to object identifiers, allowing developers to integrate rapid search functionality without storing raw document content directly within the search engine. The system distinguishes itself through a specialized graph-based index that enables real-time word prediction and typo correction. Communication is handled via a custom, low-latency binary protocol over raw TCP sockets, which

    Includes built-in utilities for auditing dependencies to maintain a secure software supply chain.

    Rustbackenddatabasegraph
    Ver en GitHub↗21,249
  • nautechsystems/nautilus_traderAvatar de nautechsystems

    nautechsystems/nautilus_trader

    20,056Ver en GitHub↗

    Nautilus Trader is a high-performance algorithmic trading framework built in Rust, designed for the development, backtesting, and live execution of automated trading strategies. It provides a comprehensive platform for managing multi-asset portfolios and interacting with diverse financial markets through a standardized connectivity suite. The system is engineered to handle high-frequency data processing and complex order execution while maintaining precise numerical accuracy across various asset classes. The framework distinguishes itself through an architecture centered on deterministic even

    Scans project dependencies against security databases to identify vulnerabilities and unsound code.

    Rustalgorithmic-trading-engineartificial-intelligencecrypto-trading
    Ver en GitHub↗20,056
  • github/opensource.guideAvatar de github

    github/opensource.guide

    15,530Ver en GitHub↗

    This project serves as a comprehensive repository of best practices and documentation standards for managing open source software. It provides a foundational framework for establishing project governance, defining contributor roles, and structuring the lifecycle of collaborative software development. By centralizing knowledge on community building and operational transparency, it acts as a guide for launching, maintaining, and scaling healthy software projects. The project distinguishes itself by offering actionable strategies for the human and organizational aspects of software development t

    Monitors project dependencies for known vulnerabilities and automates the creation of security updates.

    HTMLbest-practicesdocumentationhacktoberfest
    Ver en GitHub↗15,530
  • quarkusio/quarkusAvatar de quarkusio

    quarkusio/quarkus

    15,479Ver en GitHub↗

    Quarkus is a Kubernetes-native Java framework designed for building high-performance, memory-efficient applications. It utilizes ahead-of-time native compilation to transform Java code into standalone, optimized binaries that eliminate the need for a virtual machine, enabling rapid startup and reduced memory consumption. By performing code augmentation during the build phase, it shifts heavy processing tasks away from runtime, ensuring that applications are optimized for cloud-native environments. The framework distinguishes itself through a unified approach to reactive and imperative program

    Identifies security flaws in project dependencies during the build process.

    Javacloud-nativehacktoberfestjava
    Ver en GitHub↗15,479
  • analysis-tools-dev/static-analysisAvatar de analysis-tools-dev

    analysis-tools-dev/static-analysis

    14,389Ver en GitHub↗

    This project is a comprehensive, curated directory of static analysis, linting, and security scanning utilities. It serves as a central resource for developers to discover, compare, and select tools based on specific programming languages, licensing models, and integration requirements. The directory distinguishes itself by providing deep metadata for each listed utility, including community-driven popularity rankings, maintenance status, and deployment methods. By aggregating these tools into a single searchable index, it enables teams to identify solutions for enforcing coding standards, ma

    Audits project dependency manifests against vulnerability databases to identify insecure or outdated third-party libraries.

    Rustanalysisawesome-listcode-quality
    Ver en GitHub↗14,389
  • asyncfuncai/deepwiki-openAvatar de AsyncFuncAI

    AsyncFuncAI/deepwiki-open

    14,362Ver en GitHub↗

    This platform is an automated documentation and codebase analysis system designed to generate structured wikis, technical guides, and interactive diagrams from source code repositories. It functions as a retrieval-augmented generation framework that connects codebases to language models, enabling context-aware answers, deep research, and automated documentation updates through semantic vector search. The system distinguishes itself through a self-hosted, containerized architecture that supports both cloud-based and local AI model execution. It provides sophisticated model orchestration, allow

    Schedules recurring scans and applies patches to project dependencies to mitigate vulnerabilities in the underlying infrastructure.

    Pythonaigeminigithub
    Ver en GitHub↗14,362
  • future-architect/vulsAvatar de future-architect

    future-architect/vuls

    12,185Ver en GitHub↗

    Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit

    Analyzes programming language libraries and website plugins to find vulnerabilities via lockfiles.

    Go
    Ver en GitHub↗12,185
  • nvidia/skillspectorAvatar de NVIDIA

    NVIDIA/SkillSpector

    10,778Ver en GitHub↗

    SkillSpector es un escáner de seguridad diseñado para detectar vulnerabilidades y patrones maliciosos en plugins y extensiones de agentes de IA antes de que sean instalados. Funciona como un guardrail en tiempo de ejecución que calcula puntuaciones de riesgo numéricas y asigna etiquetas de severidad para proporcionar recomendaciones de instalación o bloquear extensiones externas arriesgadas. El proyecto se distingue por utilizar modelos de lenguaje para realizar análisis de código semántico, evaluando la intención y el contexto del código para reducir los falsos positivos. También emplea la supresión de problemas basada en huellas digitales para rastrear e ignorar riesgos previamente aceptados a través de ciclos de escaneo repetidos. La herramienta cubre la seguridad de la cadena de suministro de software mediante el escaneo de dependencias contra bases de datos de seguridad públicas y admite la ingesta de activos de múltiples fuentes desde directorios locales, URLs remotas y repositorios. Proporciona informes de vulnerabilidad en múltiples formatos legibles por máquina y por humanos para su integración en pipelines de CI/CD.

    Identifies known vulnerabilities in third-party dependencies by querying public security databases.

    Python
    Ver en GitHub↗10,778
  • nasa/fprimeAvatar de nasa

    nasa/fprime

    10,766Ver en GitHub↗

    F Prime es un framework basado en componentes diseñado para el desarrollo y despliegue de software embebido y de vuelo espacial. Proporciona una arquitectura modular que desacopla la lógica del software de las interfaces de comunicación, permitiendo a los desarrolladores definir estructuras de sistema mediante un lenguaje de modelado específico del dominio. Este enfoque basado en modelos permite la generación automática de código, asegurando la consistencia en topologías de sistemas complejos mientras mantiene estrictos contratos de interfaz entre los módulos de software. El framework se distingue por su sistema de compilación integrado y su suite de operaciones de datos en tierra. Automatiza todo el ciclo de vida del software embebido, desde la compilación cruzada y la gestión de dependencias hasta la generación de interfaces de telemetría y comandos. Al proporcionar un entorno unificado tanto para el software de vuelo a bordo como para la monitorización en tierra, facilita la integración, las pruebas y el mando y control de sistemas embebidos distribuidos en diversas plataformas de hardware. Más allá de su arquitectura central, el proyecto incluye herramientas integrales para la observabilidad del sistema, incluyendo visualización de telemetría en tiempo real, registro de eventos y trazado de diagnóstico. Soporta una amplia gama de escenarios de despliegue, desde entornos bare-metal hasta sistemas operativos en tiempo real, y proporciona mecanismos para la gestión de memoria, modelado de comportamiento basado en estados y ejecución de tareas asíncronas. El proyecto se mantiene como un repositorio en C++ con documentación extensa y soporte de sistema de compilación para el desarrollo multiplataforma.

    Analyzes software inventory files against security databases to identify risks and vulnerabilities in project components.

    C++componentscppembedded
    Ver en GitHub↗10,766
  • google/osv-scannerAvatar de google

    google/osv-scanner

    10,565Ver en GitHub↗

    osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and container images against the Open Source Vulnerabilities database. It functions as a dependency remediation tool and can be integrated into custom Go applications as a programmable security library. The project distinguishes itself through a remediation workflow that includes an interactive terminal user interface and automated scripting for upgrading vulnerable packages in lockfiles and manifests. It employs call-graph reachability analysis to determine if vulnerable code is act

    Analyzes project dependencies and container images against the Open Source Vulnerabilities database.

    Goscannersecurity-auditsecurity-tools
    Ver en GitHub↗10,565
  • npm/cliAvatar de npm

    npm/cli

    9,846Ver en GitHub↗

    This project is a command line interface for managing, installing, and publishing JavaScript packages to a remote registry. It serves as a dependency resolution tool, a software registry publishing client, and a security auditor for Node.js development workflows. The tool distinguishes itself by providing integrated monorepo workspace management and a comprehensive registry authentication client that supports multi-factor authentication. It enables detailed control over the software supply chain through provenance attestations, package signature verification, and the generation of a Software

    Analyzes project dependencies to detect known security vulnerabilities and protect the software supply chain.

    JavaScriptjavascriptnodejsnpm
    Ver en GitHub↗9,846
  • bridgecrewio/checkovAvatar de bridgecrewio

    bridgecrewio/checkov

    8,798Ver en GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Analyzes project dependencies and container images to detect known security vulnerabilities (CVEs).

    Python
    Ver en GitHub↗8,798
  • databasus/databasusAvatar de databasus

    databasus/databasus

    7,502Ver en GitHub↗

    Databasus is a self-hosted backup platform that automates PostgreSQL backups, verifies their restorability, and stores them across multiple destinations while managing team access with role-based permissions. It combines on-the-fly AES-256-GCM encryption, cron-driven scheduling, job-queue-based verification, multi-destination storage, WAL streaming, throwaway container restore testing, and workspace-based role access control into a unified backup system. The platform distinguishes itself through automatic backup verification that restores each backup into a temporary database container for in

    Monitors dependencies against the GitHub Advisory Database and blocks PRs that introduce new high or critical CVEs.

    Gobackupbackupsdatabase
    Ver en GitHub↗7,502
  • snyk/snykAvatar de snyk

    snyk/snyk

    5,586Ver en GitHub↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    Scans project dependency manifests to identify known security flaws in open-source libraries and packages.

    TypeScript
    Ver en GitHub↗5,586
  • snyk/cliAvatar de snyk

    snyk/cli

    5,428Ver en GitHub↗

    The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies, proprietary application code, container images, and infrastructure-as-code configuration files. It also serves as a platform management tool, allowing users to configure organizations, users, SSO, and reporting from the terminal rather than the web dashboard. The CLI integrates directly into development workflows, enabling scanning within IDEs, build pipelines, and version control systems. It implements static analysis with interfile data flow analysis to find complex security f

    Creates snapshots of dependencies and sends alerts when new vulnerabilities or fixes are discovered over time.

    TypeScriptmonitorsecuritysnyk
    Ver en GitHub↗5,428
Ant.12Siguiente
  1. Home
  2. Security & Cryptography
  3. Dependency Vulnerability Scanners