17 रिपॉजिटरी
Automated routines for downloading and installing security releases and maintenance patches.
Distinct from Application and System Security: Distinct from Application and System Security: focuses on the automated lifecycle of patch management rather than general security posture.
Explore 17 awesome GitHub repositories matching security & cryptography · Automated Security Patching. Refine with filters or upvote what's useful.
Distroless provides a set of OCI-compliant minimal base images and hardening tools designed to create secure, language-specific execution environments. These images are stripped of non-essential system binaries, shells, and package managers to reduce the container attack surface. The project utilizes upstream-tracked automated patching to monitor operating system releases and generate updated images when security vulnerabilities are addressed. It ensures supply chain integrity through image provenance verification using ephemeral-key digital signatures. The system supports the generation of
Monitors official operating system releases to automatically generate updated images when security vulnerabilities are fixed.
WordPress is an open-source content management system and PHP-based application framework designed for building and maintaining websites. It functions as a visual, block-based website builder that allows users to construct layouts and manage digital content without manual code entry. The platform supports a wide range of operational needs, from managing individual sites to administering complex multi-site networks from a single installation. The system is distinguished by its highly extensible, plugin-driven modular architecture, which allows for the integration of third-party modules to add
Ensures operational stability by automatically managing security releases and maintenance patches.
Tinker is an Android hotfix framework designed to update application code, resources, and native libraries at runtime without requiring a full reinstallation or store update. It provides a comprehensive engine for injecting runtime fixes and managing the software lifecycle of deployed mobile applications. The framework distinguishes itself through a robust binary patching system that generates compact difference files between application versions, significantly reducing bandwidth usage during distribution. To ensure operational stability, it incorporates a crash-resilient safe mode that autom
Verifies patch file checksums to ensure authenticity and integrity before application.
kops is a Kubernetes cluster provisioner and lifecycle manager designed to automate the creation, maintenance, and destruction of production-grade clusters on cloud infrastructure. It functions as a declarative infrastructure manager, synchronizing the live state of a cluster with versioned manifests stored in remote object storage to ensure idempotent operations. The project distinguishes itself by offering comprehensive automation for the entire cluster lifecycle, including high-availability control plane deployment, incremental rolling updates, and automated version upgrades. It also serve
Automatically applies OS-level security patches to supported distributions across the cluster nodes.
Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit
Checks operating systems for missing security updates and identifies servers that require reboots after kernel patches.
This project is a comprehensive security platform providing an LLM security orchestration framework, an AI agent firewall, and tools for vulnerability remediation, compliance automation, and endpoint protection. It functions as a centralized system to protect AI models from adversarial exploits while managing the identification and patching of software flaws. The platform distinguishes itself through the coordination of specialized AI agents to automate complex security workflows, including reconnaissance, bug hunting, and exploit development. It implements dedicated guardrails to block promp
Applies vulnerability fixes using encrypted delivery combined with automatic backup and rollback mechanisms.
Runtipi is a home server dashboard and orchestration tool designed for deploying and managing containerized applications. It provides a web-based interface for discovering and installing software from a curated app store, utilizing a Docker Compose orchestrator to handle the deployment of self-hosted services. The system integrates a reverse proxy and SSL manager to route external traffic to internal containers, automating HTTPS certificate renewal and domain assignment. It also features a built-in backup and update manager that uses cron-based scheduling to perform automatic security patchin
Automates the application of security and maintenance patches via a system scheduler.
all-in-one is a containerized deployment system designed to install and manage a complete suite of productivity and collaboration services. It functions as a cloud suite deployer that orchestrates the installation of a self-hosted content platform, incorporating necessary dependencies via Docker or Kubernetes. The project distinguishes itself by providing a web-based dashboard for orchestrating, updating, and monitoring the lifecycle of service containers. It also serves as a local AI inference server, enabling the execution of generative text models, image diffusion, and speech processing on
Allows installing security patches to fix vulnerabilities without requiring a full version upgrade.
vphone-cli is a command line interface for booting virtual iOS devices using Apple's native virtualization framework. It provides a sandboxed virtual mobile environment and tools for executing iOS system images on a host operating system. The project includes a firmware flashing utility capable of building signed ramdisks and applying custom firmware patches to virtual device boot chains. It facilitates the installation of custom firmware variants to remove system security restrictions. The toolset covers virtual device provisioning through system image restoration and security blob retrieva
Applies firmware variants to the boot chain to remove system security restrictions.
AliSQL is a fork of MySQL by Alibaba that extends the relational database management system with enhancements for high performance, scalability, and enterprise-grade availability. It retains the core MySQL identity as a SQL-based database for storing, organizing, and retrieving structured data, while adding optimizations for large-scale transactional and analytical workloads. The project differentiates itself through a set of Alibaba-specific improvements, including a columnar engine for accelerating analytical queries directly on MySQL tables, and a distributed, shared-nothing NDB Cluster en
Applies a batch of security fixes released as part of an Oracle Critical Security Patch Update to address vulnerabilities.
Dopamine is an iOS jailbreak tool designed to provide root access and administrative privileges for devices running iOS 15 and 16. It functions as a system privilege escalation exploit that grants elevated permissions without modifying the read-only system partition. The project employs a semi-untethered root exploit model, meaning it requires a manual trigger after every reboot to restore root access. This approach allows for the bypass of system restrictions and the installation of unauthorized software. The tool manages root access and system customization through a variety of low-level c
Uses a semi-untethered boot chain that requires manual activation after reboot to restore root access.
TrickyStore is an Android device integrity emulator and keystore attestation spoofer. It functions as a framework to intercept keystore calls and provide modified certificate chains and security metadata to bypass hardware attestation requirements. The project enables the injection of hardware keyboxes and the modification of key attestation certificates to simulate a secure root of trust. It allows for the overriding of security patch levels and operating system versions to mask a device's identity and state from third party applications. The system includes capabilities for application-spe
A product feature to modify or spoof the reported security patch level returned by the key attestation process.
Windows-Exploit-Suggester is a security analysis tool designed to audit patch levels and identify vulnerabilities on Windows hosts. It functions as a vulnerability scanner and patch level auditor that compares installed system hotfixes against Microsoft security bulletins to detect missing updates. The project maps these missing security updates to known public exploits and available Metasploit modules. It uses a vulnerability database interface to download and query external security bulletin data, linking specific unpatched vulnerabilities to viable exploit vectors. The tool's capabilities
Audits whether a target host is up to date with the latest Microsoft security bulletins.
TacticalRMM is a remote monitoring and management platform designed for overseeing endpoints and automating IT administration. It functions as an endpoint management tool and IT automation framework, providing a centralized dashboard for executing scripts, monitoring system health, and managing remote devices across multiple tenants. The platform distinguishes itself through a comprehensive remote administration suite that includes real-time shell access, remote file management, and registry editing. It integrates with third-party remote desktop software and provides a hierarchical policy inh
Automates the application of operating system updates to endpoints based on predefined patch policies and schedules.
Flox is a Nix environment manager designed to create, share, and maintain reproducible software stacks. It uses declarative manifests to isolate project dependencies and toolchains, ensuring identical runtimes across different machines and operating systems. The platform distinguishes itself by enabling the deployment of imageless workloads to Kubernetes, allowing software to run in pods without traditional container images. It can also synthesize OCI-compliant container images and distroless artifacts directly from declarative environment definitions. The project covers broad capability are
Updates vulnerable packages in a central baseline and pushes changes to all teams.
This project is a multi-vendor marketplace platform designed for food, grocery, and courier delivery services. It provides a comprehensive system for managing the entire lifecycle of a delivery request, including customer ordering, vendor menu management, and logistics coordination between customers, vendors, and delivery agents. The platform distinguishes itself through a cross-platform architecture that bridges web-based application code into native mobile environments for deployment on standard app stores. It utilizes real-time socket communication to synchronize location updates and order
Maintains a consistent versioning policy to ensure timely delivery of security patches and vulnerability fixes.
यह प्लेटफ़ॉर्म एक व्यापक, व्हाइट-लेबल सॉफ्टवेयर सुइट है जिसे ऑन-डिमांड फूड डिलीवरी सेवाओं को लॉन्च और मैनेज करने के लिए डिज़ाइन किया गया है। यह एक एकीकृत इकोसिस्टम प्रदान करता है जो ग्राहकों, रेस्तरां कर्मचारियों और डिलीवरी राइडर्स को एकीकृत मोबाइल और वेब इंटरफेस के माध्यम से जोड़ता है, जिसे एक सेंट्रलाइज्ड बैकएंड इंफ्रास्ट्रक्चर का समर्थन प्राप्त है जो सभी यूज़र रोल्स में डेटा और बिज़नेस लॉजिक को सिंक्रोनाइज़ करता है। यह सिस्टम अपने सेल्फ-होस्टेड डिप्लॉयमेंट पर फोकस के कारण अलग है, जो ऑपरेटरों को उनके डेटा, बैकअप और सर्वर एनवायरनमेंट पर पूर्ण नियंत्रण देता है। यह मल्टी-वर्टिकल बिज़नेस मॉडल को सपोर्ट करता है, जिससे एडमिनिस्ट्रेटर एक ही सेंट्रलाइज्ड डैशबोर्ड से डिलीवरी और राइड-शेयरिंग जैसी विभिन्न सेवा प्रकारों को मैनेज कर सकते हैं। इसका आर्किटेक्चर क्रॉस-प्लेटफ़ॉर्म कंपोनेंट शेयरिंग और रियल-टाइम इवेंट हैंडलिंग का लाभ उठाता है ताकि सभी क्लाइंट एप्लिकेशन में निरंतर प्रदर्शन और लाइव ऑर्डर ट्रैकिंग सुनिश्चित की जा सके। इस प्लेटफ़ॉर्म में ऑपरेशनल टूल्स का एक पूरा सुइट शामिल है, जिसमें रेस्तरां पार्टनर एडमिनिस्ट्रेशन और मेनू मैनेजमेंट से लेकर ऑटोमेटेड लॉजिस्टिक्स कोऑर्डिनेशन और राइडर असाइनमेंट तक शामिल हैं। इसमें बिज़नेस इंटेलिजेंस फीचर्स भी शामिल हैं, जो ऑपरेशनल प्रदर्शन और यूज़र गतिविधि की निगरानी के लिए एनालिटिक्स और रिपोर्टिंग डैशबोर्ड प्रदान करते हैं। यह सॉफ्टवेयर एक्स्टेंसिबिलिटी के लिए डिज़ाइन किया गया है, जिससे विशिष्ट बिज़नेस आवश्यकताओं को पूरा करने के लिए सोर्स कोड में संशोधन और रीब्रांडिंग की जा सकती है।
Maintains a supported versioning policy to apply critical security patches to active software releases.