quinzhi's starred repositories

advisory-database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

License:CC-BY-4.0Stargazers:1719Issues:0Issues:0

purl-spec

A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

License:NOASSERTIONStargazers:680Issues:0Issues:0

bom-examples

A repository with examples of CycloneDX BOMs (SBOM, SaaSBOM, OBOM, VEX, etc)

License:CC0-1.0Stargazers:169Issues:0Issues:0

cve-bin-tool

The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 200 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

Language:PythonLicense:GPL-3.0Stargazers:1191Issues:0Issues:0

pyt

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Language:PythonLicense:GPL-2.0Stargazers:2172Issues:0Issues:0

synopsys-detect

Scanning and analysis for Synopsys products.

Language:JavaLicense:Apache-2.0Stargazers:156Issues:0Issues:0
Language:JavaLicense:Apache-2.0Stargazers:20Issues:0Issues:0

shc

Shell script compiler

Language:CLicense:GPL-3.0Stargazers:2012Issues:0Issues:0

docker-drag

Download image from the Docker Hub HTTPS API

Language:PythonLicense:GPL-3.0Stargazers:692Issues:0Issues:0

trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Language:GoLicense:Apache-2.0Stargazers:23102Issues:0Issues:0

dpkg-licenses

A command line tool which lists the licenses of all installed packages in a Debian-based system (like Ubuntu)

Language:ShellLicense:GPL-3.0Stargazers:167Issues:0Issues:0

rpm-parser

Produce a list of dependencies from an RPM database file

Language:TypeScriptLicense:NOASSERTIONStargazers:6Issues:0Issues:0

syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Language:GoLicense:Apache-2.0Stargazers:6068Issues:0Issues:0

cli

Snyk CLI scans and monitors your projects for security vulnerabilities.

Language:TypeScriptLicense:NOASSERTIONStargazers:4910Issues:0Issues:0

grype

A vulnerability scanner for container images and filesystems

Language:GoLicense:Apache-2.0Stargazers:8577Issues:0Issues:0

codechecker

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy

Language:PythonLicense:Apache-2.0Stargazers:2230Issues:0Issues:0

Bear

Bear is a tool that generates a compilation database for clang tooling.

Language:C++License:GPL-3.0Stargazers:4830Issues:0Issues:0

cs-self-learning

计算机自学指南

Language:HTMLLicense:MITStargazers:56299Issues:0Issues:0

jd-gui

A standalone Java Decompiler GUI

Language:JavaLicense:GPL-3.0Stargazers:13972Issues:0Issues:0

Elkeid

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.

Language:GoStargazers:2235Issues:0Issues:0

spring-framework

Spring Framework

Language:JavaLicense:Apache-2.0Stargazers:56344Issues:0Issues:0

yasca

Yet Another Source Code Analyzer

Language:PHPStargazers:184Issues:0Issues:0

llvm-project

The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.

Language:LLVMLicense:NOASSERTIONStargazers:28311Issues:0Issues:0

sunlogin_rce

向日葵 RCE

Language:GoStargazers:481Issues:0Issues:0

dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Language:JavaLicense:Apache-2.0Stargazers:2614Issues:0Issues:0

PinTools

Pintool example and PoC for dynamic binary analysis

Language:C++Stargazers:579Issues:0Issues:0

yaml-vfs

A gem which can gen VFS YAML file.

Language:Objective-CLicense:MITStargazers:18Issues:0Issues:0

grammars-v4

Grammars written for ANTLR v4; expectation that the grammars are free of actions.

Language:ANTLRLicense:MITStargazers:10123Issues:0Issues:0

pmd

An extensible multilanguage static code analyzer.

Language:JavaLicense:NOASSERTIONStargazers:4836Issues:0Issues:0

moby

The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems

Language:GoLicense:Apache-2.0Stargazers:68553Issues:0Issues:0