awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

28 个仓库

Awesome GitHub RepositoriesVulnerability Reporting

Platforms and processes that allow researchers and users to disclose discovered security flaws to developers.

Explore 28 awesome GitHub repositories matching security & cryptography · Vulnerability Reporting. Refine with filters or upvote what's useful.

Awesome Vulnerability Reporting GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • addyosmani/agent-skillsaddyosmani 的头像

    addyosmani/agent-skills

    60,849在 GitHub 上查看↗

    Agent-skills is a collection of structured instructions and behavioral personas designed to standardize how AI coding agents perform engineering tasks. It functions as a workflow orchestrator that maps natural language intent to repeatable technical sequences and verification checklists. The project distinguishes itself through the use of specialized markdown-defined roles, such as security auditors or test engineers, to apply targeted domain expertise. It employs an evidence-based verification model that requires runtime data or passing tests as mandatory exit criteria to ensure AI-generated

    Categorizes security findings by risk level based on exploitability and impact to prioritize remediation.

    Shellagent-skillsantigravityantigravity-ide
    在 GitHub 上查看↗60,849
  • rails/railsrails 的头像

    rails/rails

    58,690在 GitHub 上查看↗

    This project is a full-stack web framework designed for building database-backed applications through a standardized architectural pattern. It provides a comprehensive suite of integrated libraries that manage the entire request-response lifecycle, from routing incoming web traffic to rendering dynamic server-side templates. By utilizing an object-relational mapping layer, the framework allows developers to define domain models that map database tables directly to application objects, simplifying data persistence, schema migrations, and complex relationship management. The framework is distin

    Maintains a transparent disclosure process for managing and reviewing reported security vulnerabilities.

    Rubyactivejobactiverecordframework
    在 GitHub 上查看↗58,690
  • projectdiscovery/nucleiprojectdiscovery 的头像

    projectdiscovery/nuclei

    29,189在 GitHub 上查看↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Assigns custom severity levels to security templates to align with internal risk assessment requirements.

    Goattack-surfacecve-scannerdast
    在 GitHub 上查看↗29,189
  • docker-slim/docker-slimdocker-slim 的头像

    docker-slim/docker-slim

    23,311在 GitHub 上查看↗

    This project is a suite of specialized tools for linting, minifying, analyzing, and managing container images and their associated registries. It provides a set of utilities including an image minifier to reduce image size, a security profiler to harden running containers, an image analyzer for static inspection, and a registry manager for organizing multi-architecture indices. The toolset distinguishes itself through behavior-based optimization and security. It uses dynamic analysis to track executed instructions and file access to remove unused binary data, and records kernel interactions t

    Retrieves and filters risk information for specific security IDs to assess threat levels within container images.

    Go
    在 GitHub 上查看↗23,311
  • fallibleinc/security-guide-for-developersFallibleInc 的头像

    FallibleInc/security-guide-for-developers

    21,090在 GitHub 上查看↗

    This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which

    Provides contextual analysis and statistical data to help teams prioritize vulnerability patching efforts.

    在 GitHub 上查看↗21,090
  • carlospolop/privilege-escalation-awesome-scripts-suitecarlospolop 的头像

    carlospolop/privilege-escalation-awesome-scripts-suite

    20,003在 GitHub 上查看↗

    This project is a post-exploitation framework and privilege escalation script suite designed to scan local system configurations for security gaps. It serves as a system enumeration toolset used to identify paths for gaining higher administrative privileges on a target host. The suite incorporates capabilities for security penetration testing and vulnerability assessment reporting. It uses shell-based system enumeration and pattern-based vulnerability matching to detect misconfigurations, while employing heuristic-based permission analysis to evaluate system flags. Findings are gathered thro

    Converts raw system scan data into structured formats like JSON or PDF for security documentation.

    C#
    在 GitHub 上查看↗20,003
  • smicallef/spiderfootsmicallef 的头像

    smicallef/spiderfoot

    18,189在 GitHub 上查看↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Produces contextualized analysis and remediation strategies to help security teams evaluate risks and prioritize patching efforts.

    Pythonattacksurfacecticybersecurity
    在 GitHub 上查看↗18,189
  • projectdiscovery/subfinderprojectdiscovery 的头像

    projectdiscovery/subfinder

    13,105在 GitHub 上查看↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Outputs structured vulnerability details for integration into automated analysis pipelines.

    Gobugbountyhackinghacktoberfest
    在 GitHub 上查看↗13,105
  • misskey-dev/misskeymisskey-dev 的头像

    misskey-dev/misskey

    11,213在 GitHub 上查看↗

    Misskey is a self-hosted, decentralized microblogging platform and federated social media server. It functions as a distributed content management system that allows users to communicate across multiple independent and interconnected server instances using the ActivityPub protocol. The platform distinguishes itself with a dynamic application engine that allows for the creation of interactive applications and custom page layouts using a scripting language. It also features a specialized markup language for rich text rendering, enabling the use of animations and custom styles for consistent con

    Provides a private channel for the responsible disclosure and reporting of discovered security vulnerabilities.

    TypeScriptactivitypubfederationfediverse
    在 GitHub 上查看↗11,213
  • coreos/claircoreos 的头像

    coreos/clair

    11,011在 GitHub 上查看↗

    Clair is a container vulnerability scanner that performs static analysis of container images to identify known security vulnerabilities. It functions as an analyzer for OCI and Docker images, indexing their contents to detect security risks and outdated packages without requiring the containers to be running. The tool identifies vulnerabilities by matching indexed container components against security databases to find common vulnerabilities and exposures. This process involves analyzing filesystem layers to track the provenance and versioning of packages across the image hierarchy. The proj

    Performs security assessments on container images by analyzing layers and packages against vulnerability IDs.

    Go
    在 GitHub 上查看↗11,011
  • quay/clairquay 的头像

    quay/clair

    11,012在 GitHub 上查看↗

    Clair is a container image vulnerability scanner and security analyzer. It performs static analysis of container images by matching package contents against vulnerability databases to identify security risks across different package formats and architectures. The project functions as both an image indexer and a vulnerability database manager. It processes container layers into intermediate representations to enable fast security lookups and synchronizes security metadata from multiple external sources to maintain a local registry. Capability areas include continuous security monitoring, whic

    Analyzes container images to correlate contents with known security vulnerabilities based on risk levels.

    Goclaircontainersdocker
    在 GitHub 上查看↗11,012
  • google/osv-scannergoogle 的头像

    google/osv-scanner

    10,565在 GitHub 上查看↗

    osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and container images against the Open Source Vulnerabilities database. It functions as a dependency remediation tool and can be integrated into custom Go applications as a programmable security library. The project distinguishes itself through a remediation workflow that includes an interactive terminal user interface and automated scripting for upgrading vulnerable packages in lockfiles and manifests. It employs call-graph reachability analysis to determine if vulnerable code is act

    Uses call analysis to determine if a vulnerable function is actually invoked to reduce false positives.

    Goscannersecurity-auditsecurity-tools
    在 GitHub 上查看↗10,565
  • veeral-patel/how-to-secure-anythingveeral-patel 的头像

    veeral-patel/how-to-secure-anything

    10,224在 GitHub 上查看↗

    This project is a comprehensive security suite and knowledge base focused on the engineering and construction of trustworthy digital and physical systems. It provides a systematic framework for security engineering design, covering the establishment of high-assurance architectures and the implementation of security models that govern how a system achieves its safety goals. The project is distinguished by its focus on formal assurance and adversarial deterrence. It includes methodologies for creating security assurance cases and proofs to verify system trustworthiness, alongside economic and t

    Analyzes multi-step attack paths to identify where security controls can most effectively break the kill chain.

    secure-designsecure-systemssecurity
    在 GitHub 上查看↗10,224
  • boto/boto3boto 的头像

    boto/boto3

    9,834在 GitHub 上查看↗

    Boto3 is the AWS SDK for Python, providing a programmatic interface for managing and automating AWS cloud infrastructure and services. It serves as a cloud management API client and resource manager for provisioning, configuring, and scaling virtual servers, databases, and storage. The library enables the implementation of infrastructure-as-code through declarative templates and scripts, allowing for the deployment of identical resource stacks across multiple accounts and geographic regions. It also provides a framework for coordinating distributed workflows, serverless functions, and contain

    Analyzes container images upon upload to identify and assess software vulnerabilities.

    Pythonawsaws-sdkcloud
    在 GitHub 上查看↗9,834
  • 0x4m4/hexstrike-ai0x4m4 的头像

    0x4m4/hexstrike-ai

    9,617在 GitHub 上查看↗

    This project is a comprehensive security platform providing an LLM security orchestration framework, an AI agent firewall, and tools for vulnerability remediation, compliance automation, and endpoint protection. It functions as a centralized system to protect AI models from adversarial exploits while managing the identification and patching of software flaws. The platform distinguishes itself through the coordination of specialized AI agents to automate complex security workflows, including reconnaissance, bug hunting, and exploit development. It implements dedicated guardrails to block promp

    Identifies technology stacks and correlates intelligence to discover potential attack chains for optimized tool selection.

    Python0x4m4aiai-agents
    在 GitHub 上查看↗9,617
  • google/tsunami-security-scannergoogle 的头像

    google/tsunami-security-scanner

    8,584在 GitHub 上查看↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Identifies and reports critical security vulnerabilities in network environments using automated probes.

    Java
    在 GitHub 上查看↗8,584
  • yandex/gixyyandex 的头像

    yandex/gixy

    8,570在 GitHub 上查看↗

    Gixy is a static configuration analyzer and security auditor for Nginx. It functions as an infrastructure-as-code security scanner and web server configuration linter designed to identify vulnerabilities and misconfigurations in server definitions before deployment. The tool focuses on detecting high-risk security flaws, including host header spoofing, server-side request forgery, and path traversal. It specifically audits Nginx configurations for risks such as HTTP splitting, multiline header issues, and unauthorized third-party access resulting from incorrect Referer or Origin header patter

    Assigns severity levels to detected Nginx misconfigurations to help prioritize remediation efforts.

    Python
    在 GitHub 上查看↗8,570
  • collabnix/dockerlabscollabnix 的头像

    collabnix/dockerlabs

    8,008在 GitHub 上查看↗

    dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of containerization and microservice architecture. It provides instructional material and hands-on exercises covering image optimization, security training, infrastructure setup, and cluster orchestration. The project features specific courses and guides focused on reducing image size through multi-stage builds, securing workloads via vulnerability scanning and encrypted networks, and deploying multi-node clusters with high availability using Swarm orchestration. The materials cover a br

    Includes training on scanning container images for security vulnerabilities and software flaws.

    PHPadvancebeginnersdocker
    在 GitHub 上查看↗8,008
  • presidentbeef/brakemanpresidentbeef 的头像

    presidentbeef/brakeman

    7,248在 GitHub 上查看↗

    Brakeman is a static analysis security tool and scanner specifically designed for Ruby on Rails source code. It identifies common security vulnerabilities, such as injection and cross-site scripting, by analyzing the application codebase without executing the application. The tool functions as a security auditor that detects mass assignment risks and template vulnerabilities. It evaluates the final output of rendered views and identifies unrestricted assignment patterns that could allow unauthorized modification of model attributes. The system provides vulnerability management through the us

    Assigns risk levels and certainty scores to identified vulnerabilities to help prioritize remediation.

    Ruby
    在 GitHub 上查看↗7,248
  • anthropics/defending-code-reference-harnessanthropics 的头像

    anthropics/defending-code-reference-harness

    6,224在 GitHub 上查看↗

    该项目是一个使用大语言模型代理进行安全漏洞自动发现和修复的框架。它作为一个安全研究管道,自动化侦察、崩溃发现和可利用性分析过程,以识别可重现的软件错误。 该系统通过利用限制网络出口和文件系统访问以防止宿主机受损的容器化代理沙箱而脱颖而出。它采用专门的补丁生成和验证循环,其中包括对抗性重攻击测试,即由新代理尝试使用新输入绕过建议的修复程序,以确保修复的有效性。 该框架涵盖了广泛的安全功能,包括静态漏洞分析、攻击面划分和威胁模型构建。它提供了通过崩溃签名聚类和去重进行漏洞分类的工具,以及执行大规模代码迁移以在整个代码库中应用系统性修复的能力。

    Generates structured reports detailing primitive classes, reachability, and escalation paths to analyze crash exploitability.

    Python
    在 GitHub 上查看↗6,224
上一个12下一个
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Vulnerability Reporting

探索子标签

  • Contextual Vulnerability Analysis4 个子标签Tools for producing contextualized analysis and remediation strategies to help teams prioritize patching efforts. **Distinct from Vulnerability Reporting:** Distinct from Vulnerability Reporting: focuses on contextual analysis and remediation strategy rather than disclosure protocols.
  • Severity Customization1 个子标签Tools for assigning custom risk levels to vulnerability findings. **Distinct from Vulnerability Reporting:** Distinct from Vulnerability Reporting: focuses on internal risk alignment rather than external disclosure.