awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

28 repository-uri

Awesome GitHub RepositoriesVulnerability Reporting

Platforms and processes that allow researchers and users to disclose discovered security flaws to developers.

Explore 28 awesome GitHub repositories matching security & cryptography · Vulnerability Reporting. Refine with filters or upvote what's useful.

Awesome Vulnerability Reporting GitHub Repositories

Găsește cele mai bune repo-uri cu AI.Vom căuta cele mai potrivite repository-uri folosind AI.
  • addyosmani/agent-skillsAvatar addyosmani

    addyosmani/agent-skills

    60,849Vezi pe GitHub↗

    Agent-skills is a collection of structured instructions and behavioral personas designed to standardize how AI coding agents perform engineering tasks. It functions as a workflow orchestrator that maps natural language intent to repeatable technical sequences and verification checklists. The project distinguishes itself through the use of specialized markdown-defined roles, such as security auditors or test engineers, to apply targeted domain expertise. It employs an evidence-based verification model that requires runtime data or passing tests as mandatory exit criteria to ensure AI-generated

    Categorizes security findings by risk level based on exploitability and impact to prioritize remediation.

    Shellagent-skillsantigravityantigravity-ide
    Vezi pe GitHub↗60,849
  • rails/railsAvatar rails

    rails/rails

    58,690Vezi pe GitHub↗

    This project is a full-stack web framework designed for building database-backed applications through a standardized architectural pattern. It provides a comprehensive suite of integrated libraries that manage the entire request-response lifecycle, from routing incoming web traffic to rendering dynamic server-side templates. By utilizing an object-relational mapping layer, the framework allows developers to define domain models that map database tables directly to application objects, simplifying data persistence, schema migrations, and complex relationship management. The framework is distin

    Maintains a transparent disclosure process for managing and reviewing reported security vulnerabilities.

    Rubyactivejobactiverecordframework
    Vezi pe GitHub↗58,690
  • projectdiscovery/nucleiAvatar projectdiscovery

    projectdiscovery/nuclei

    29,189Vezi pe GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Assigns custom severity levels to security templates to align with internal risk assessment requirements.

    Goattack-surfacecve-scannerdast
    Vezi pe GitHub↗29,189
  • docker-slim/docker-slimAvatar docker-slim

    docker-slim/docker-slim

    23,311Vezi pe GitHub↗

    This project is a suite of specialized tools for linting, minifying, analyzing, and managing container images and their associated registries. It provides a set of utilities including an image minifier to reduce image size, a security profiler to harden running containers, an image analyzer for static inspection, and a registry manager for organizing multi-architecture indices. The toolset distinguishes itself through behavior-based optimization and security. It uses dynamic analysis to track executed instructions and file access to remove unused binary data, and records kernel interactions t

    Retrieves and filters risk information for specific security IDs to assess threat levels within container images.

    Go
    Vezi pe GitHub↗23,311
  • fallibleinc/security-guide-for-developersAvatar FallibleInc

    FallibleInc/security-guide-for-developers

    21,090Vezi pe GitHub↗

    This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which

    Provides contextual analysis and statistical data to help teams prioritize vulnerability patching efforts.

    Vezi pe GitHub↗21,090
  • carlospolop/privilege-escalation-awesome-scripts-suiteAvatar carlospolop

    carlospolop/privilege-escalation-awesome-scripts-suite

    20,003Vezi pe GitHub↗

    This project is a post-exploitation framework and privilege escalation script suite designed to scan local system configurations for security gaps. It serves as a system enumeration toolset used to identify paths for gaining higher administrative privileges on a target host. The suite incorporates capabilities for security penetration testing and vulnerability assessment reporting. It uses shell-based system enumeration and pattern-based vulnerability matching to detect misconfigurations, while employing heuristic-based permission analysis to evaluate system flags. Findings are gathered thro

    Converts raw system scan data into structured formats like JSON or PDF for security documentation.

    C#
    Vezi pe GitHub↗20,003
  • smicallef/spiderfootAvatar smicallef

    smicallef/spiderfoot

    18,189Vezi pe GitHub↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Produces contextualized analysis and remediation strategies to help security teams evaluate risks and prioritize patching efforts.

    Pythonattacksurfacecticybersecurity
    Vezi pe GitHub↗18,189
  • projectdiscovery/subfinderAvatar projectdiscovery

    projectdiscovery/subfinder

    13,105Vezi pe GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Outputs structured vulnerability details for integration into automated analysis pipelines.

    Gobugbountyhackinghacktoberfest
    Vezi pe GitHub↗13,105
  • misskey-dev/misskeyAvatar misskey-dev

    misskey-dev/misskey

    11,213Vezi pe GitHub↗

    Misskey is a self-hosted, decentralized microblogging platform and federated social media server. It functions as a distributed content management system that allows users to communicate across multiple independent and interconnected server instances using the ActivityPub protocol. The platform distinguishes itself with a dynamic application engine that allows for the creation of interactive applications and custom page layouts using a scripting language. It also features a specialized markup language for rich text rendering, enabling the use of animations and custom styles for consistent con

    Provides a private channel for the responsible disclosure and reporting of discovered security vulnerabilities.

    TypeScriptactivitypubfederationfediverse
    Vezi pe GitHub↗11,213
  • coreos/clairAvatar coreos

    coreos/clair

    11,011Vezi pe GitHub↗

    Clair is a container vulnerability scanner that performs static analysis of container images to identify known security vulnerabilities. It functions as an analyzer for OCI and Docker images, indexing their contents to detect security risks and outdated packages without requiring the containers to be running. The tool identifies vulnerabilities by matching indexed container components against security databases to find common vulnerabilities and exposures. This process involves analyzing filesystem layers to track the provenance and versioning of packages across the image hierarchy. The proj

    Performs security assessments on container images by analyzing layers and packages against vulnerability IDs.

    Go
    Vezi pe GitHub↗11,011
  • quay/clairAvatar quay

    quay/clair

    11,012Vezi pe GitHub↗

    Clair is a container image vulnerability scanner and security analyzer. It performs static analysis of container images by matching package contents against vulnerability databases to identify security risks across different package formats and architectures. The project functions as both an image indexer and a vulnerability database manager. It processes container layers into intermediate representations to enable fast security lookups and synchronizes security metadata from multiple external sources to maintain a local registry. Capability areas include continuous security monitoring, whic

    Analyzes container images to correlate contents with known security vulnerabilities based on risk levels.

    Goclaircontainersdocker
    Vezi pe GitHub↗11,012
  • google/osv-scannerAvatar google

    google/osv-scanner

    10,565Vezi pe GitHub↗

    osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and container images against the Open Source Vulnerabilities database. It functions as a dependency remediation tool and can be integrated into custom Go applications as a programmable security library. The project distinguishes itself through a remediation workflow that includes an interactive terminal user interface and automated scripting for upgrading vulnerable packages in lockfiles and manifests. It employs call-graph reachability analysis to determine if vulnerable code is act

    Uses call analysis to determine if a vulnerable function is actually invoked to reduce false positives.

    Goscannersecurity-auditsecurity-tools
    Vezi pe GitHub↗10,565
  • veeral-patel/how-to-secure-anythingAvatar veeral-patel

    veeral-patel/how-to-secure-anything

    10,224Vezi pe GitHub↗

    This project is a comprehensive security suite and knowledge base focused on the engineering and construction of trustworthy digital and physical systems. It provides a systematic framework for security engineering design, covering the establishment of high-assurance architectures and the implementation of security models that govern how a system achieves its safety goals. The project is distinguished by its focus on formal assurance and adversarial deterrence. It includes methodologies for creating security assurance cases and proofs to verify system trustworthiness, alongside economic and t

    Analyzes multi-step attack paths to identify where security controls can most effectively break the kill chain.

    secure-designsecure-systemssecurity
    Vezi pe GitHub↗10,224
  • boto/boto3Avatar boto

    boto/boto3

    9,834Vezi pe GitHub↗

    Boto3 is the AWS SDK for Python, providing a programmatic interface for managing and automating AWS cloud infrastructure and services. It serves as a cloud management API client and resource manager for provisioning, configuring, and scaling virtual servers, databases, and storage. The library enables the implementation of infrastructure-as-code through declarative templates and scripts, allowing for the deployment of identical resource stacks across multiple accounts and geographic regions. It also provides a framework for coordinating distributed workflows, serverless functions, and contain

    Analyzes container images upon upload to identify and assess software vulnerabilities.

    Pythonawsaws-sdkcloud
    Vezi pe GitHub↗9,834
  • 0x4m4/hexstrike-aiAvatar 0x4m4

    0x4m4/hexstrike-ai

    9,617Vezi pe GitHub↗

    This project is a comprehensive security platform providing an LLM security orchestration framework, an AI agent firewall, and tools for vulnerability remediation, compliance automation, and endpoint protection. It functions as a centralized system to protect AI models from adversarial exploits while managing the identification and patching of software flaws. The platform distinguishes itself through the coordination of specialized AI agents to automate complex security workflows, including reconnaissance, bug hunting, and exploit development. It implements dedicated guardrails to block promp

    Identifies technology stacks and correlates intelligence to discover potential attack chains for optimized tool selection.

    Python0x4m4aiai-agents
    Vezi pe GitHub↗9,617
  • google/tsunami-security-scannerAvatar google

    google/tsunami-security-scanner

    8,584Vezi pe GitHub↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Identifies and reports critical security vulnerabilities in network environments using automated probes.

    Java
    Vezi pe GitHub↗8,584
  • yandex/gixyAvatar yandex

    yandex/gixy

    8,570Vezi pe GitHub↗

    Gixy is a static configuration analyzer and security auditor for Nginx. It functions as an infrastructure-as-code security scanner and web server configuration linter designed to identify vulnerabilities and misconfigurations in server definitions before deployment. The tool focuses on detecting high-risk security flaws, including host header spoofing, server-side request forgery, and path traversal. It specifically audits Nginx configurations for risks such as HTTP splitting, multiline header issues, and unauthorized third-party access resulting from incorrect Referer or Origin header patter

    Assigns severity levels to detected Nginx misconfigurations to help prioritize remediation efforts.

    Python
    Vezi pe GitHub↗8,570
  • collabnix/dockerlabsAvatar collabnix

    collabnix/dockerlabs

    8,008Vezi pe GitHub↗

    dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of containerization and microservice architecture. It provides instructional material and hands-on exercises covering image optimization, security training, infrastructure setup, and cluster orchestration. The project features specific courses and guides focused on reducing image size through multi-stage builds, securing workloads via vulnerability scanning and encrypted networks, and deploying multi-node clusters with high availability using Swarm orchestration. The materials cover a br

    Includes training on scanning container images for security vulnerabilities and software flaws.

    PHPadvancebeginnersdocker
    Vezi pe GitHub↗8,008
  • presidentbeef/brakemanAvatar presidentbeef

    presidentbeef/brakeman

    7,248Vezi pe GitHub↗

    Brakeman is a static analysis security tool and scanner specifically designed for Ruby on Rails source code. It identifies common security vulnerabilities, such as injection and cross-site scripting, by analyzing the application codebase without executing the application. The tool functions as a security auditor that detects mass assignment risks and template vulnerabilities. It evaluates the final output of rendered views and identifies unrestricted assignment patterns that could allow unauthorized modification of model attributes. The system provides vulnerability management through the us

    Assigns risk levels and certainty scores to identified vulnerabilities to help prioritize remediation.

    Ruby
    Vezi pe GitHub↗7,248
  • anthropics/defending-code-reference-harnessAvatar anthropics

    anthropics/defending-code-reference-harness

    6,224Vezi pe GitHub↗

    Acest proiect este un framework pentru descoperirea și remedierea autonomă a vulnerabilităților de securitate folosind agenți de tip large language model. Acesta funcționează ca un pipeline de cercetare în securitate care automatizează procesul de recunoaștere, descoperire a crash-urilor și analiză a exploatabilității pentru a identifica bug-uri software reproductibile. Sistemul se distinge prin utilizarea unui sandbox de agenți containerizat care restricționează ieșirea în rețea și accesul la sistemul de fișiere pentru a preveni compromiterea gazdei. Utilizează o buclă specializată de generare și validare a patch-urilor, care include testarea de re-atac adversarial, unde un agent nou încearcă să ocolească remedierile propuse cu noi input-uri pentru a asigura eficiența remedierii. Framework-ul acoperă o gamă largă de capabilități de securitate, inclusiv analiza statică a vulnerabilităților, partiționarea suprafeței de atac și construcția modelului de amenințare. Oferă instrumente pentru triajul vulnerabilităților prin clustering-ul semnăturilor de crash și deduplicare, precum și capacitatea de a executa migrări de cod la scară largă pentru a aplica remedieri sistemice în întregul codebase.

    Generates structured reports detailing primitive classes, reachability, and escalation paths to analyze crash exploitability.

    Python
    Vezi pe GitHub↗6,224
Înapoi12Înainte
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Vulnerability Reporting

Explorează sub-etichetele

  • Contextual Vulnerability Analysis4 sub-tag-uriTools for producing contextualized analysis and remediation strategies to help teams prioritize patching efforts. **Distinct from Vulnerability Reporting:** Distinct from Vulnerability Reporting: focuses on contextual analysis and remediation strategy rather than disclosure protocols.
  • Severity Customization1 sub-tagTools for assigning custom risk levels to vulnerability findings. **Distinct from Vulnerability Reporting:** Distinct from Vulnerability Reporting: focuses on internal risk alignment rather than external disclosure.