#owasp (30 Repositories)
Ranked open-source repositories tagged with #owasp, scored by pull request acceptance likelihood and maintainer engagement velocity.
54.7%
23.4h
30 repositories tagged #owasp
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
CycloneDX/cyclonedx-gomod
Creates CycloneDX Software Bill of Materials (SBOM) from Go modules
OWASP/www-community
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
corazawaf/libinjection-go
libinjection is a Golang port of the libinjection(https://github.com/client9/libinjection)
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
OWASP/threat-dragon
An open source threat modeling tool from OWASP
CycloneDX/cyclonedx-core-java
CycloneDX SBOM Model and Utils for Creating and Validating BOMs
DefectDojo/django-DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
OWASP/www-project-agent-memory-guard
OWASP Foundation web repository
OWASP/cornucopia
The source files and tools needed to build the OWASP Cornucopia decks in various languages
OWASP/www-project-secure-headers
The OWASP Secure Headers Project
GaProgMan/OwaspHeaders.Core
Inject OWASP recommended HTTP Headers for increased security in a single line
OWASP/wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
corazawaf/coraza
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
Agent-Threat-Rule/agent-threat-rules
Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents. Executable rules across 10 categories; merged into Microsoft AGT, Cisco AI Defense, MISP, OWASP, FINOS & SigmaHQ. MIT-licensed.
CycloneDX/cyclonedx-go
Go library to consume and produce CycloneDX Software Bill of Materials (SBOM)
coreruleset/coreruleset
OWASP CRS (Official Repository)
owasp-amass/amass
In-depth attack surface mapping and asset discovery
vitalysim/Awesome-Hacking-Resources
A collection of hacking / penetration testing resources to make you better!
juice-shop/juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
0xffsec/handbook
A living document for penetration testing and offensive security.
OWASP/Python-Honeypot
OWASP Honeypot, Automated Deception Framework.
mindedsecurity/semgrep-rules-android-security
A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.
secureCodeBox/secureCodeBox
secureCodeBox (SCB) - continuous secure delivery out of the box
juice-shop/multi-juicer
Host and manage multiple Juice Shop instances for security trainings and Capture The Flags
OWASP/DockSec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Feysh-Group/corax-community
Corax for Java: A general static analysis framework for java code checking.