software-security topic
keyshuffling
Keyshuffling Attack for Persistent Early Code Execution in the Nintendo 3DS Secure Bootchain
nist-data-mirror
A simple Java command-line utility to mirror the CVE JSON data from NIST.
threatmodel-sdk
A Java library for parsing and programmatically using threat models
vulndb-data-mirror
A simple Java command-line utility to mirror the entire contents of VulnDB.
sbt-dependency-check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). :rainbow:
cve
Gather and update all available and newest CVEs with their PoC.
dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
dependency-check-sonar-plugin
Integrates Dependency-Check reports into SonarQube
macbook
《macOS软件安全与逆向分析》随书源码
specification
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, and V...