Todas las etiquetas
Etiqueta del catálogo

#owasp

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

48 registros
Con la etiqueta «owasp»Ordenado por índice de salud
npm · Go · crates.io
96Excepcionalíndice de salud
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 6138↓ 14.7K/mes28 ago 2026
MIT28 ago 2026 · métricas 2.10.0
PyPI
95Excepcionalíndice de salud
CycloneDX/cyclonedx-python
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Python★ 390↓ 2.2M/mes27 ago 2026
Apache-2.027 ago 2026 · métricas 2.10.0
npm · RubyGems
95Excepcionalíndice de salud
owasp/threat-dragon
An open source threat modeling tool from OWASP
JavaScript · Vue★ 152315 jul 2026
Apache-2.015 jul 2026 · métricas 2.10.0
npm · crates.io
94Excepcionalíndice de salud
AikidoSec/firewall-node
Zen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.
TypeScript · JavaScript★ 201↓ 179.4K/mes22 jul 2026
Licencia propia22 jul 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 2.10.0
PyPI · npm
94Excepcionalíndice de salud
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2808/mes2 ago 2026
MIT2 ago 2026 · métricas 2.10.0
npm · Maven · NuGet +1
92Excelenteíndice de salud
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1018↓ 745.3K/mes28 jul 2026
Apache-2.028 jul 2026 · métricas 2.10.0
npm
91Excelenteíndice de salud
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1266↓ 2624/mes23 jul 2026
AGPL-3.023 jul 2026 · métricas 2.10.0
Packagist
91Excelenteíndice de salud
CycloneDX/cyclonedx-php-composer
Create CycloneDX Software Bill of Materials (SBOM) from PHP Composer projects
PHP★ 87↓ 91.9K/mes29 jul 2026
Apache-2.029 jul 2026 · métricas 2.10.0
PyPI
90Excelenteíndice de salud
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 11317 jul 2026
Apache-2.017 jul 2026 · métricas 2.10.0
PyPI · RubyGems
90Excelenteíndice de salud
OWASP/www-project-agent-memory-guard
OWASP Foundation web repository
Python★ 155↓ 2902/mes25 ago 2026
Apache-2.025 ago 2026 · métricas 2.10.0
89Excelenteíndice de salud
owasp-noir/noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
Crystal★ 13634 ago 2026
MIT4 ago 2026 · métricas 2.10.0
PyPI
89Excelenteíndice de salud
owasp/docksec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 46017 jul 2026
MIT17 jul 2026 · métricas 2.10.0
npm
88Excelenteíndice de salud
OWASP/cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
TypeScript★ 635↓ 20.2K/mes16 jul 2026
MIT16 jul 2026 · métricas 2.10.0
npm
88Excelenteíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5893/mes6 sept 2026
MIT6 sept 2026 · métricas 2.10.0
PyPI
88Excelenteíndice de salud
jimmy058910/jmo-security-repo
JMo Security Suite - Terminal-first security audit toolkit with many tools, multi-target scanning, & compliance
Python★ 731 jul 2026
Licencia propia31 jul 2026 · métricas 2.10.0
Go
88Excelenteíndice de salud
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14617 jul 2026
Licencia propia17 jul 2026 · métricas 2.10.0
Go
87Excelenteíndice de salud
l3montree-dev/flawfix
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14618 jul 2026
Licencia propia18 jul 2026 · métricas 2.10.0
npm
86Excelenteíndice de salud
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/mes25 jul 2026
MIT25 jul 2026 · métricas 2.10.0
npm
84Excelenteíndice de salud
KeygraphHQ/shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3414/mes5 ago 2026
AGPL-3.05 ago 2026 · métricas 2.10.0
npm · Go
84Excelenteíndice de salud
daveshanley/vacuum
vacuum is the worlds fastest and most versatile OpenAPI, AsyncAPI & JSON Schema linter, docs generator and toolkit. It tears through API specs at light speed. 100% compatible with Spectral rulesets, and OpenAPI 3.0, 3.1 and 3.2
Go★ 1103↓ 169.8K/mes19 jul 2026
MIT19 jul 2026 · métricas 2.10.0
npm · PyPI
84Excelenteíndice de salud
openshield-org/openshield
Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with one command
Python · JavaScript★ 554 ago 2026
MIT4 ago 2026 · métricas 2.10.0
83Excelenteíndice de salud
CycloneDX/cyclonedx-cli
CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.
C#★ 53321 ago 2026
Apache-2.021 ago 2026 · métricas 2.10.0
NuGet
83Excelenteíndice de salud
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 2822 jul 2026
Apache-2.022 jul 2026 · métricas 2.10.0
Maven
83Excelenteíndice de salud
CycloneDX/cyclonedx-maven-plugin
Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects
Java★ 37530 jul 2026
Apache-2.030 jul 2026 · métricas 2.10.0
npm · PyPI
81Excelenteíndice de salud
Agent-Threat-Rule/agent-threat-rules
Open detection standard -- like Sigma, but for AI agents. 425 rules, shipped in Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H. 97.1% recall on NVIDIA garak. NIST OSCAL Path 1.
TypeScript★ 314↓ 9370/mes16 jul 2026
MIT16 jul 2026 · métricas 2.10.0
Go
81Excelenteíndice de salud
CycloneDX/sbom-utility
Utility that provides an API platform for validating, querying and managing BOM data
Go★ 1633 sept 2026
Apache-2.03 sept 2026 · métricas 2.10.0
Go
81Excelenteíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 823 jul 2026
Apache-2.023 jul 2026 · métricas 2.10.0
npm
80Excelenteíndice de salud
lua-ai-global/governance
Zero-dependency TypeScript SDK for AI agent governance: policy enforcement, injection detection, tamper-evident audit, and standards mapping (EU AI Act, OWASP, NIST, ISO 42001)
TypeScript★ 25↓ 3545/mes26 jul 2026
MIT26 jul 2026 · métricas 2.10.0
npm
78Buenoíndice de salud
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/mes4 ago 2026
Licencia propia4 ago 2026 · métricas 2.10.0