awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

28 रिपॉजिटरी

Awesome GitHub RepositoriesVulnerability Reporting

Platforms and processes that allow researchers and users to disclose discovered security flaws to developers.

Explore 28 awesome GitHub repositories matching security & cryptography · Vulnerability Reporting. Refine with filters or upvote what's useful.

Awesome Vulnerability Reporting GitHub Repositories

AI के साथ बेहतरीन रिपॉजिटरी खोजें।हम AI का उपयोग करके सबसे सटीक रिपॉजिटरी खोजेंगे।
  • addyosmani/agent-skillsaddyosmani का अवतार

    addyosmani/agent-skills

    60,849GitHub पर देखें↗

    Agent-skills is a collection of structured instructions and behavioral personas designed to standardize how AI coding agents perform engineering tasks. It functions as a workflow orchestrator that maps natural language intent to repeatable technical sequences and verification checklists. The project distinguishes itself through the use of specialized markdown-defined roles, such as security auditors or test engineers, to apply targeted domain expertise. It employs an evidence-based verification model that requires runtime data or passing tests as mandatory exit criteria to ensure AI-generated

    Categorizes security findings by risk level based on exploitability and impact to prioritize remediation.

    Shellagent-skillsantigravityantigravity-ide
    GitHub पर देखें↗60,849
  • rails/railsrails का अवतार

    rails/rails

    58,690GitHub पर देखें↗

    This project is a full-stack web framework designed for building database-backed applications through a standardized architectural pattern. It provides a comprehensive suite of integrated libraries that manage the entire request-response lifecycle, from routing incoming web traffic to rendering dynamic server-side templates. By utilizing an object-relational mapping layer, the framework allows developers to define domain models that map database tables directly to application objects, simplifying data persistence, schema migrations, and complex relationship management. The framework is distin

    Maintains a transparent disclosure process for managing and reviewing reported security vulnerabilities.

    Rubyactivejobactiverecordframework
    GitHub पर देखें↗58,690
  • projectdiscovery/nucleiprojectdiscovery का अवतार

    projectdiscovery/nuclei

    29,189GitHub पर देखें↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Assigns custom severity levels to security templates to align with internal risk assessment requirements.

    Goattack-surfacecve-scannerdast
    GitHub पर देखें↗29,189
  • docker-slim/docker-slimdocker-slim का अवतार

    docker-slim/docker-slim

    23,311GitHub पर देखें↗

    This project is a suite of specialized tools for linting, minifying, analyzing, and managing container images and their associated registries. It provides a set of utilities including an image minifier to reduce image size, a security profiler to harden running containers, an image analyzer for static inspection, and a registry manager for organizing multi-architecture indices. The toolset distinguishes itself through behavior-based optimization and security. It uses dynamic analysis to track executed instructions and file access to remove unused binary data, and records kernel interactions t

    Retrieves and filters risk information for specific security IDs to assess threat levels within container images.

    Go
    GitHub पर देखें↗23,311
  • fallibleinc/security-guide-for-developersFallibleInc का अवतार

    FallibleInc/security-guide-for-developers

    21,090GitHub पर देखें↗

    This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which

    Provides contextual analysis and statistical data to help teams prioritize vulnerability patching efforts.

    GitHub पर देखें↗21,090
  • carlospolop/privilege-escalation-awesome-scripts-suitecarlospolop का अवतार

    carlospolop/privilege-escalation-awesome-scripts-suite

    20,003GitHub पर देखें↗

    This project is a post-exploitation framework and privilege escalation script suite designed to scan local system configurations for security gaps. It serves as a system enumeration toolset used to identify paths for gaining higher administrative privileges on a target host. The suite incorporates capabilities for security penetration testing and vulnerability assessment reporting. It uses shell-based system enumeration and pattern-based vulnerability matching to detect misconfigurations, while employing heuristic-based permission analysis to evaluate system flags. Findings are gathered thro

    Converts raw system scan data into structured formats like JSON or PDF for security documentation.

    C#
    GitHub पर देखें↗20,003
  • smicallef/spiderfootsmicallef का अवतार

    smicallef/spiderfoot

    18,189GitHub पर देखें↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Produces contextualized analysis and remediation strategies to help security teams evaluate risks and prioritize patching efforts.

    Pythonattacksurfacecticybersecurity
    GitHub पर देखें↗18,189
  • projectdiscovery/subfinderprojectdiscovery का अवतार

    projectdiscovery/subfinder

    13,105GitHub पर देखें↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Outputs structured vulnerability details for integration into automated analysis pipelines.

    Gobugbountyhackinghacktoberfest
    GitHub पर देखें↗13,105
  • misskey-dev/misskeymisskey-dev का अवतार

    misskey-dev/misskey

    11,213GitHub पर देखें↗

    Misskey is a self-hosted, decentralized microblogging platform and federated social media server. It functions as a distributed content management system that allows users to communicate across multiple independent and interconnected server instances using the ActivityPub protocol. The platform distinguishes itself with a dynamic application engine that allows for the creation of interactive applications and custom page layouts using a scripting language. It also features a specialized markup language for rich text rendering, enabling the use of animations and custom styles for consistent con

    Provides a private channel for the responsible disclosure and reporting of discovered security vulnerabilities.

    TypeScriptactivitypubfederationfediverse
    GitHub पर देखें↗11,213
  • coreos/claircoreos का अवतार

    coreos/clair

    11,011GitHub पर देखें↗

    Clair is a container vulnerability scanner that performs static analysis of container images to identify known security vulnerabilities. It functions as an analyzer for OCI and Docker images, indexing their contents to detect security risks and outdated packages without requiring the containers to be running. The tool identifies vulnerabilities by matching indexed container components against security databases to find common vulnerabilities and exposures. This process involves analyzing filesystem layers to track the provenance and versioning of packages across the image hierarchy. The proj

    Performs security assessments on container images by analyzing layers and packages against vulnerability IDs.

    Go
    GitHub पर देखें↗11,011
  • quay/clairquay का अवतार

    quay/clair

    11,012GitHub पर देखें↗

    Clair is a container image vulnerability scanner and security analyzer. It performs static analysis of container images by matching package contents against vulnerability databases to identify security risks across different package formats and architectures. The project functions as both an image indexer and a vulnerability database manager. It processes container layers into intermediate representations to enable fast security lookups and synchronizes security metadata from multiple external sources to maintain a local registry. Capability areas include continuous security monitoring, whic

    Analyzes container images to correlate contents with known security vulnerabilities based on risk levels.

    Goclaircontainersdocker
    GitHub पर देखें↗11,012
  • google/osv-scannergoogle का अवतार

    google/osv-scanner

    10,565GitHub पर देखें↗

    osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and container images against the Open Source Vulnerabilities database. It functions as a dependency remediation tool and can be integrated into custom Go applications as a programmable security library. The project distinguishes itself through a remediation workflow that includes an interactive terminal user interface and automated scripting for upgrading vulnerable packages in lockfiles and manifests. It employs call-graph reachability analysis to determine if vulnerable code is act

    Uses call analysis to determine if a vulnerable function is actually invoked to reduce false positives.

    Goscannersecurity-auditsecurity-tools
    GitHub पर देखें↗10,565
  • veeral-patel/how-to-secure-anythingveeral-patel का अवतार

    veeral-patel/how-to-secure-anything

    10,224GitHub पर देखें↗

    This project is a comprehensive security suite and knowledge base focused on the engineering and construction of trustworthy digital and physical systems. It provides a systematic framework for security engineering design, covering the establishment of high-assurance architectures and the implementation of security models that govern how a system achieves its safety goals. The project is distinguished by its focus on formal assurance and adversarial deterrence. It includes methodologies for creating security assurance cases and proofs to verify system trustworthiness, alongside economic and t

    Analyzes multi-step attack paths to identify where security controls can most effectively break the kill chain.

    secure-designsecure-systemssecurity
    GitHub पर देखें↗10,224
  • boto/boto3boto का अवतार

    boto/boto3

    9,834GitHub पर देखें↗

    Boto3 is the AWS SDK for Python, providing a programmatic interface for managing and automating AWS cloud infrastructure and services. It serves as a cloud management API client and resource manager for provisioning, configuring, and scaling virtual servers, databases, and storage. The library enables the implementation of infrastructure-as-code through declarative templates and scripts, allowing for the deployment of identical resource stacks across multiple accounts and geographic regions. It also provides a framework for coordinating distributed workflows, serverless functions, and contain

    Analyzes container images upon upload to identify and assess software vulnerabilities.

    Pythonawsaws-sdkcloud
    GitHub पर देखें↗9,834
  • 0x4m4/hexstrike-ai0x4m4 का अवतार

    0x4m4/hexstrike-ai

    9,617GitHub पर देखें↗

    This project is a comprehensive security platform providing an LLM security orchestration framework, an AI agent firewall, and tools for vulnerability remediation, compliance automation, and endpoint protection. It functions as a centralized system to protect AI models from adversarial exploits while managing the identification and patching of software flaws. The platform distinguishes itself through the coordination of specialized AI agents to automate complex security workflows, including reconnaissance, bug hunting, and exploit development. It implements dedicated guardrails to block promp

    Identifies technology stacks and correlates intelligence to discover potential attack chains for optimized tool selection.

    Python0x4m4aiai-agents
    GitHub पर देखें↗9,617
  • google/tsunami-security-scannergoogle का अवतार

    google/tsunami-security-scanner

    8,584GitHub पर देखें↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Identifies and reports critical security vulnerabilities in network environments using automated probes.

    Java
    GitHub पर देखें↗8,584
  • yandex/gixyyandex का अवतार

    yandex/gixy

    8,570GitHub पर देखें↗

    Gixy is a static configuration analyzer and security auditor for Nginx. It functions as an infrastructure-as-code security scanner and web server configuration linter designed to identify vulnerabilities and misconfigurations in server definitions before deployment. The tool focuses on detecting high-risk security flaws, including host header spoofing, server-side request forgery, and path traversal. It specifically audits Nginx configurations for risks such as HTTP splitting, multiline header issues, and unauthorized third-party access resulting from incorrect Referer or Origin header patter

    Assigns severity levels to detected Nginx misconfigurations to help prioritize remediation efforts.

    Python
    GitHub पर देखें↗8,570
  • collabnix/dockerlabscollabnix का अवतार

    collabnix/dockerlabs

    8,008GitHub पर देखें↗

    dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of containerization and microservice architecture. It provides instructional material and hands-on exercises covering image optimization, security training, infrastructure setup, and cluster orchestration. The project features specific courses and guides focused on reducing image size through multi-stage builds, securing workloads via vulnerability scanning and encrypted networks, and deploying multi-node clusters with high availability using Swarm orchestration. The materials cover a br

    Includes training on scanning container images for security vulnerabilities and software flaws.

    PHPadvancebeginnersdocker
    GitHub पर देखें↗8,008
  • presidentbeef/brakemanpresidentbeef का अवतार

    presidentbeef/brakeman

    7,248GitHub पर देखें↗

    Brakeman is a static analysis security tool and scanner specifically designed for Ruby on Rails source code. It identifies common security vulnerabilities, such as injection and cross-site scripting, by analyzing the application codebase without executing the application. The tool functions as a security auditor that detects mass assignment risks and template vulnerabilities. It evaluates the final output of rendered views and identifies unrestricted assignment patterns that could allow unauthorized modification of model attributes. The system provides vulnerability management through the us

    Assigns risk levels and certainty scores to identified vulnerabilities to help prioritize remediation.

    Ruby
    GitHub पर देखें↗7,248
  • anthropics/defending-code-reference-harnessanthropics का अवतार

    anthropics/defending-code-reference-harness

    6,224GitHub पर देखें↗

    यह प्रोजेक्ट बड़े भाषा मॉडल (LLM) एजेंटों का उपयोग करके सुरक्षा कमजोरियों की स्वायत्त खोज और सुधार के लिए एक फ्रेमवर्क है। यह एक सुरक्षा अनुसंधान पाइपलाइन के रूप में कार्य करता है जो पुनरुत्पादक सॉफ्टवेयर बग्स की पहचान करने के लिए टोही, क्रैश डिस्कवरी और एक्सप्लॉइटेबिलिटी विश्लेषण की प्रक्रिया को स्वचालित करती है। यह सिस्टम एक कंटेनरीकृत एजेंट सैंडबॉक्स का उपयोग करके खुद को अलग करता है जो होस्ट कॉम्प्रोमाइज़ को रोकने के लिए नेटवर्क एग्रेस और फाइल सिस्टम एक्सेस को प्रतिबंधित करता है। यह एक विशेष पैच जनरेशन और वैलिडेशन लूप को नियोजित करता है, जिसमें एडवरसैरियल री-अटैक टेस्टिंग शामिल है जहाँ एक नया एजेंट सुधार की प्रभावशीलता सुनिश्चित करने के लिए नए इनपुट के साथ प्रस्तावित फिक्स को बायपास करने का प्रयास करता है। यह फ्रेमवर्क स्टेटिक भेद्यता विश्लेषण, अटैक सरफेस पार्टिशनिंग और थ्रेट मॉडल निर्माण सहित सुरक्षा क्षमताओं की एक विस्तृत श्रृंखला को कवर करता है। यह क्रैश सिग्नेचर क्लस्टरिंग और डिडुप्लीकेशन के माध्यम से भेद्यता ट्राइएज के लिए टूल्स प्रदान करता है, साथ ही कोडबेस में व्यवस्थित सुधार लागू करने के लिए बड़े पैमाने पर कोड माइग्रेशन निष्पादित करने की क्षमता भी प्रदान करता है।

    Generates structured reports detailing primitive classes, reachability, and escalation paths to analyze crash exploitability.

    Python
    GitHub पर देखें↗6,224
पिछला12अगला
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Vulnerability Reporting

सब-टैग एक्सप्लोर करें

  • Contextual Vulnerability Analysis4 सब-टैग्सTools for producing contextualized analysis and remediation strategies to help teams prioritize patching efforts. **Distinct from Vulnerability Reporting:** Distinct from Vulnerability Reporting: focuses on contextual analysis and remediation strategy rather than disclosure protocols.
  • Severity Customization1 सब-टैगTools for assigning custom risk levels to vulnerability findings. **Distinct from Vulnerability Reporting:** Distinct from Vulnerability Reporting: focuses on internal risk alignment rather than external disclosure.